Skip to content

[CRITICAL] Sandbox disabled in browser window configuration #103

@Tsukieomie

Description

@Tsukieomie

Security Issue: Sandbox Disabled

Severity: CRITICAL
Location: src/main/windows/main.ts:361

Description

The Electron browser window has sandbox: false explicitly set, which disables Electron's sandbox protection. This is currently required for electron-trpc but creates a significant security vulnerability.

Code

sandbox: false  // Required for electron-trpc (commented)

Risk

Disables Electron's sandbox protection, allowing the renderer process to access Node.js APIs if context isolation is breached.

Recommendation

  1. Investigate if electron-trpc has sandbox-safe alternatives
  2. Research alternative IPC mechanisms that support sandboxing
  3. Document the security tradeoff if sandboxing cannot be enabled
  4. Consider using @electron/remote or custom IPC bridge as alternatives

References

Labels: security, critical, electron

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions