Back

HIGH

Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions

Published Sep 29, 2026

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

Affected products

Remediation

Red Hat statement

A flaw was found in Electron where an embedded <webview> guest can enable nodeIntegrationInWorker for background Web Workers even when Node.js integration is disabled in the unsandboxed embedder. Untrusted guest content loaded inside a web view can exploit this behavior to spawn a Node-enabled worker, bypassing host security restrictions to achieve privilege escalation and arbitrary code execution within the context of the host application process.

Red Hat mitigation

Disable the <webview> tag in application configurations or ensure the host embedder process remains strictly sandboxed.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 29, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Awaiting Analysis
Modified Sep 30, 2026
Red Hat
Severity Important
Public date Sep 29, 2026
GHSA-9QH4-3JW8-366W