BoostIO/BoostNote-App

BoostIO/BoostNote-App

Releases133
Frequency2 weeks 19 hours
Last Release
Stars4.05K
Boost Note is a document driven project management tool that maximizes remote DevOps team velocity.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.