Vulnerability Description
Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Usebruno | Bruno | < 1.29.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/opcod3r/ab69f36d52367df7ffac32a597dff31cExploitThird Party Advisory
- https://github.com/usebruno/bruno/pull/3122Issue TrackingPatch
- https://github.com/usebruno/bruno/releases/tag/v1.29.1Release Notes
- https://www.usebruno.com/changelogRelease Notes
- http://seclists.org/fulldisclosure/2025/Jan/6ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2024-48463?
CVE-2024-48463 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.
How severe is CVE-2024-48463?
CVE-2024-48463 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48463?
Check the references section above for vendor advisories and patch information. Affected products include: Usebruno Bruno.