CVE-2023-40168

TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a malicious project or custom extension to read arbitrary files from disk and upload them to a remote server. The only required user interaction is opening the sb3 file or loading the extension. The web version of TurboWarp is not affected. This bug has been addressed in commit `55e07e99b59` after an initial fix which was reverted. Users are advised to upgrade to version 1.8.0 or later. Users unable to upgrade should avoid opening sb3 files or loading extensions from untrusted sources.
Configurations

Configuration 1 (hide)

cpe:2.3:a:turbowarp:turbowarp_desktop:*:*:*:*:*:*:*:*

History

24 Aug 2023, 15:04

Type Values Removed Values Added
First Time Turbowarp
Turbowarp turbowarp Desktop
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:turbowarp:turbowarp_desktop:*:*:*:*:*:*:*:*
References (MISC) https://github.com/TurboWarp/desktop/commit/a62dbd7a28b41857e3b6f32443fda0527d493267 - (MISC) https://github.com/TurboWarp/desktop/commit/a62dbd7a28b41857e3b6f32443fda0527d493267 - Patch
References (MISC) https://github.com/TurboWarp/desktop/commit/f0f82aaf6cc8170e9da8b36953c98bfe533c019f - (MISC) https://github.com/TurboWarp/desktop/commit/f0f82aaf6cc8170e9da8b36953c98bfe533c019f - Patch
References (MISC) https://github.com/TurboWarp/desktop/security/advisories/GHSA-wg4p-vj7h-q82q - (MISC) https://github.com/TurboWarp/desktop/security/advisories/GHSA-wg4p-vj7h-q82q - Mitigation, Patch, Vendor Advisory
References (MISC) https://github.com/TurboWarp/desktop/commit/55e07e99b59db334d75e8f46792a1569ab0884a6 - (MISC) https://github.com/TurboWarp/desktop/commit/55e07e99b59db334d75e8f46792a1569ab0884a6 - Patch

17 Aug 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-17 20:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-40168

Mitre link : CVE-2023-40168

CVE.ORG link : CVE-2023-40168


JSON object : View

Products Affected

turbowarp

  • turbowarp_desktop
CWE
CWE-863

Incorrect Authorization