CVE-2025-51387
04.08.2025, 21:15
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.
| Vendor | Product | Version |
|---|---|---|
| axosoft | gitkraken_desktop | 10.8.0 |
| axosoft | gitkraken_desktop | 11.1.0 |
𝑥
= Vulnerable software versions