Jan v0.5.14 and before is vulnerable to remote code...
Critical severity
Unreviewed
Published
May 9, 2025
to the GitHub Advisory Database
•
Updated May 12, 2025
Description
Published by the National Vulnerability Database
May 9, 2025
Published to the GitHub Advisory Database
May 9, 2025
Last updated
May 12, 2025
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell.openExternal().
References