The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
History

Tue, 12 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Gitkraken
Gitkraken desktop
Vendors & Products Gitkraken
Gitkraken desktop

Tue, 05 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 Aug 2025 21:00:00 +0000

Type Values Removed Values Added
Description The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-04T00:00:00.000Z

Updated: 2025-08-05T13:44:34.597Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51387

cve-icon Vulnrichment

Updated: 2025-08-05T13:44:28.915Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-04T21:15:30.530

Modified: 2025-08-05T14:34:17.327

Link: CVE-2025-51387

cve-icon Redhat

No data.