VulnerabilityAnalyzed
CVE-2024-23755
ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses.
HIGH 8.8EPSS 1.05%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- clickup/clickup
- Source
- cve@mitre.org
References
- https://clickup.com/security/disclosuresVendor Advisory
- https://clickup.com/terms/security-policyNot Applicable
- https://www.electronjs.org/blog/statement-run-as-node-cvesNot Applicable
- https://www.electronjs.org/docs/latest/tutorial/fusesNot Applicable
- https://clickup.com/security/disclosuresVendor Advisory
- https://clickup.com/terms/security-policyNot Applicable
- https://www.electronjs.org/blog/statement-run-as-node-cvesNot Applicable
- https://www.electronjs.org/docs/latest/tutorial/fusesNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.