Resource / Blogs /

MassCode Code Execution (CVE-2020-8548)

How an XSS in massCode's markdown editor escalated to code execution (CVE-2020-8548) because the Electron app had nodeIntegration enabled.
By
Nikhil Mittal
February 4, 2020
2–3 mins
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Key Takeaways

  • massCode, an open-source Electron snippet manager, had an XSS flaw in its markdown editor.
  • Script tags did not execute, but an anchor tag with a javascript: URL triggered the XSS.
  • nodeIntegration was set to true, so injected code could call Node APIs.
  • The XSS escalated to code execution, opening Windows Calculator via Electron's shell module.
  • The issue, tracked as CVE-2020-8548, was fixed in a later massCode release.

A few days back I was looking for a tool to maintain my notes and important code snippets and I came across a tool called massCode.

About massCode

massCode is one of the free and open-source code snippet manager tool build with the electron. Sometime back it was in trending on GitHub and also listed on electron website https://www.electronjs.org/apps/masscode

massCode code snippet manager website

massCode makrdown editor

You can select different programming languages to render respecting code snippets but my interest was in markdown editor. Here is a quick image of how massCode markdown editor works

Markdown source in the massCode editor
Rendered markdown preview in massCode

XSS in massCode makrdown editor

Next, As usual, I tried to inject the script tag to see if it gets executed

Script tag payload typed into the massCode markdown editor

But nothing happened.

Script tag payload not executing in the massCode preview

Again i tried to inject <a> tag as shown in below image

Anchor tag with a javascript: payload in the massCode markdown editor

and luckily it worked this time. easy-peasy

JavaScript alert triggered through XSS in massCode

Code execution in massCode

Since massCode is built on electron and we have XSS vulnerability at the same time. I quickly navigate to the source code available on GitHub, and figured out that nodeIntegration flag is set to true.

which means we can invoke node API’s. Next I created a simple XSS payload to open a calculator on windows

nodeIntegration set to true in the massCode BrowserWindow config
<a href="javascript:try{ const {shell} = require('electron'); shell.openExternal('file:C:/Windows/System32/calc.exe') }catch(e){alert(e)}">aaaaaaa</a>
PoC opening Windows Calculator from massCode

This issue has been fixed in latest relase of massCode

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Nikhil Mittal
Ex-Bandit
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.