Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
Published Sep 29, 2026
7.4
HIGHCVSS 3.1
EPSS 0.21%
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.
Affected products
-
- Version < 41.10.6StatusaffectedConstraints-
- Version >= 42.0.0-alpha.1, < 42.9.2StatusaffectedConstraints-
- Version >= 43.0.0-alpha.1, < 43.4.1StatusaffectedConstraints-
- Version >= 44.0.0-alpha.1, < 44.0.0-beta.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Build of Podman Desktop
rh-podman-desktop
Affected
Red Hat Enterprise Linux 10
podman-desktop
Affected
Red Hat Enterprise Linux 10
rh-podman-desktop
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop | Affected | n/a |
| Red Hat Enterprise Linux 10 | podman-desktop | Affected | n/a |
| Red Hat Enterprise Linux 10 | rh-podman-desktop | Affected | n/a |
electron
npm
Introduced 0 Fixed 41.10.6electron
npm
Introduced 42.0.0-alpha.1 Fixed 42.9.2electron
npm
Introduced 43.0.0-alpha.1 Fixed 43.4.1electron
npm
Introduced 44.0.0-alpha.1 Fixed 44.0.0-beta.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 0 | 41.10.6 |
| npm | electron | 42.0.0-alpha.1 | 42.9.2 |
| npm | electron | 43.0.0-alpha.1 | 43.4.1 |
| npm | electron | 44.0.0-alpha.1 | 44.0.0-beta.5 |
Remediation
Red Hat statement
A flaw was found in Electron where responses served via protocol.registerFileProtocol or protocol.registerHttpProtocol for custom schemes registered with supportFetchAPI enabled but corsEnabled disabled remain script-readable across origins. If untrusted content is loaded within the same session, an attacker can exploit this behavior to bypass the same-origin policy and read sensitive application data, resulting in information disclosure.
Red Hat mitigation
Ensure custom schemes registered with supportFetchAPI explicitly enable corsEnabled, or avoid loading untrusted web content within sessions where custom protocol schemes with disabled CORS controls are registered.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-102675 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543317 Issue Tracking
- https://github.com/advisories/GHSA-j84w-jfhq-vhvj Advisory
- https://github.com/electron/electron/commit/4d2784cc8592471ee2276235b8c2a03efddf937d x_refsource_MISC
- https://github.com/electron/electron/commit/80178e4631cb2f6a5e42f8e793b2ae9624e78a0d x_refsource_MISC
- https://github.com/electron/electron/commit/c595b05976e7a885465b043d17e00a92fc3c3397 x_refsource_MISC
- https://github.com/electron/electron/commit/ef75c4b98caaa3ebc615f1eba302027028ee04d2 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v41.10.6 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v42.9.2 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v43.4.1 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v44.0.0-beta.5 x_refsource_MISC
- https://github.com/electron/electron/security/advisories/GHSA-j84w-jfhq-vhvj x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102675
- https://www.cve.org/CVERecord?id=CVE-2026-102675
Change history (0)
No recorded changes yet.