The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
References
Link | Resource |
---|---|
https://github.com/r3ggi/electroniz3r | Not Applicable |
https://packetstorm.news/files/id/207677 | Broken Link |
https://www.electronjs.org/blog/statement-run-as-node-cves#mitigation | Mitigation |
Configurations
Configuration 1 (hide)
|
History
09 Oct 2025, 17:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:axosoft:gitkraken_desktop:10.8.0:*:*:*:*:*:*:* cpe:2.3:a:axosoft:gitkraken_desktop:11.1.0:*:*:*:*:*:*:* |
|
First Time |
Axosoft
Axosoft gitkraken Desktop |
|
References | () https://github.com/r3ggi/electroniz3r - Not Applicable | |
References | () https://packetstorm.news/files/id/207677 - Broken Link | |
References | () https://www.electronjs.org/blog/statement-run-as-node-cves#mitigation - Mitigation |
05 Aug 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
04 Aug 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-04 21:15
Updated : 2025-10-09 17:31
NVD link : CVE-2025-51387
Mitre link : CVE-2025-51387
CVE.ORG link : CVE-2025-51387
JSON object : View
Products Affected
axosoft
- gitkraken_desktop
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')