CVE-2025-51387 Details
Description
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
A code injection vulnerability has been identified in GitKraken Desktop versions 10.8.0 and 11.1.0. This issue arises from misconfigured Electron fuses, specifically with 'runAsNode' enabled and 'enableNodeCliInspectArguments' not disabled. These settings allow the application to run in Node.js mode, where attackers can pass arguments that lead to arbitrary code execution.
Users can mitigate this vulnerability by updating to GitKraken Desktop version 11.2.1, where the issue has been addressed. Additionally, Electron applications can disable the 'runAsNode' fuse to enhance security, although this may require adjustments in how the application handles Node.js processes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/r3ggi/electroniz3r | [email protected] | Not Applicable |
| https://packetstorm.news/files/id/207677 | [email protected] | Broken Link |
| https://www.electronjs.org/blog/statement-run-as-node-cves#mitigation | [email protected] | Mitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| axosoft gitkraken desktop | 10.8.0 11.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Aug 5, 2025 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | New CVE Received | [email protected] |