Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
Published Sep 29, 2026
8.2
HIGHCVSS 3.1
EPSS 0.27%
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the Electron application's full origin instead of the restricted origin intended by the sandbox. Applications that deny such popups with setWindowOpenHandler are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.
Affected products
-
- Version < 41.10.6StatusaffectedConstraints-
- Version >= 42.0.0-alpha.1, < 42.9.2StatusaffectedConstraints-
- Version >= 43.0.0-alpha.1, < 43.4.1StatusaffectedConstraints-
- Version >= 44.0.0-alpha.1, < 44.0.0-beta.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Build of Podman Desktop
rh-podman-desktop
Affected
Red Hat Enterprise Linux 10
podman-desktop
Affected
Red Hat Enterprise Linux 10
rh-podman-desktop
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop | Affected | n/a |
| Red Hat Enterprise Linux 10 | podman-desktop | Affected | n/a |
| Red Hat Enterprise Linux 10 | rh-podman-desktop | Affected | n/a |
electron
npm
Introduced 43.0.0-alpha.1 Fixed 43.4.1electron
npm
Introduced 44.0.0-alpha.1 Fixed 44.0.0-beta.5electron
npm
Introduced 0 Fixed 41.10.6electron
npm
Introduced 42.0.0-alpha.1 Fixed 42.9.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 43.0.0-alpha.1 | 43.4.1 |
| npm | electron | 44.0.0-alpha.1 | 44.0.0-beta.5 |
| npm | electron | 0 | 41.10.6 |
| npm | electron | 42.0.0-alpha.1 | 42.9.2 |
Remediation
Red Hat statement
A flaw was found in Electron where child windows opened from a sandboxed top-level document fail to inherit the document's active HTML sandbox restrictions. An attacker capable of delivering untrusted content to a sandboxed document that is permitted to open popups can spawn a window running under the application's full origin. This leads to a sandbox bypass, enabling unauthorized access to sensitive application data or internal resources.
Red Hat mitigation
Applications can mitigate this vulnerability by intercepting and denying unexpected popups using setWindowOpenHandler. Returning { action: 'deny' } for unvalidated or unapproved popup requests prevents child windows from opening with the full origin context.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-102674 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543316 Issue Tracking
- https://github.com/advisories/GHSA-gr2m-v5gq-v685 Advisory
- https://github.com/electron/electron/commit/29fc130569f970e91e355383821a4af0f25724a2 x_refsource_MISC
- https://github.com/electron/electron/commit/3ecf3e74f4be6e2360644679b0b4698742be0e1d x_refsource_MISC
- https://github.com/electron/electron/commit/6594d5a5b074cf501da084dc7908d3df0d68a886 x_refsource_MISC
- https://github.com/electron/electron/commit/e9c4d3cbe912e18d7c63af78e63e98ae7a48cd3a x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v41.10.6 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v42.9.2 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v43.4.1 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v44.0.0-beta.5 x_refsource_MISC
- https://github.com/electron/electron/security/advisories/GHSA-gr2m-v5gq-v685 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102674
- https://www.cve.org/CVERecord?id=CVE-2026-102674
Change history (0)
No recorded changes yet.