🇫🇷 Un petit bug with a big impact.
A vulnerability reported by Doyensec's French team members in Electron's shell.openPath() has now been patched. Apps relying on string-only path validation could be tricked into opening a different file via an embedded null byte.
Merci to the Electron maintainers for the quick fix.
https://github.com/electron/electron/security/advisories/GHSA-5c9j-mhmv-5xgx