The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axosoft
Axosoft gitkraken Desktop |
|
| CPEs | cpe:2.3:a:axosoft:gitkraken_desktop:10.8.0:*:*:*:*:*:*:* cpe:2.3:a:axosoft:gitkraken_desktop:11.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Axosoft
Axosoft gitkraken Desktop |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitkraken
Gitkraken desktop |
|
| Vendors & Products |
Gitkraken
Gitkraken desktop |
Tue, 05 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Mon, 04 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-04T00:00:00.000Z
Updated: 2025-08-05T13:44:34.597Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51387
Updated: 2025-08-05T13:44:28.915Z
Status : Analyzed
Published: 2025-08-04T21:15:30.530
Modified: 2025-10-09T17:31:44.337
Link: CVE-2025-51387
No data.