Summary In electron-builder's builder-util-runtime package, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization"…
| CVE ID | CVE-2026-54673 |
| Vendor | npm |
| Affected Product | builder-util-runtime |
| Vulnerability Type | Vulnerability |
| CVSS Score | 7.5 (HIGH) |
| EPSS Score | 0.2% probability of exploitation in the next 30 days |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
#
electron-builder's builder-util-runtime package, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization". Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab's personal access token flow) and mixed-case Authorization (used by GitLab's Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination. ---HttpExecutor.prepareRedirectUrlOptions (introduced in builder-util-runtime via [PR #9211](https://github.com/electron-userland/electron-builder/pull/9211), first released in v26.0.20) performed its cross-origin credential strip with a single case-senSigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.