The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gitkraken
Gitkraken desktop |
|
Vendors & Products |
Gitkraken
Gitkraken desktop |
Tue, 05 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 | |
Metrics |
cvssV3_1
|
Mon, 04 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-04T00:00:00.000Z
Updated: 2025-08-05T13:44:34.597Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51387

Updated: 2025-08-05T13:44:28.915Z

Status : Awaiting Analysis
Published: 2025-08-04T21:15:30.530
Modified: 2025-08-05T14:34:17.327
Link: CVE-2025-51387

No data.