CVE-2023-7245: Openvpn Connect

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable

Affected products

  • Openvpn Connect: from 3.2.0, before 3.4.4 (fixed in 3.4.4); from 3.2.0, before 3.4.8 (fixed in 3.4.8); version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.1.0 only; …

Published 2024-02-20. Last modified 2026-06-17.