Electron / Electron
61 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-102677 | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer | HIGH | 7.8 | Sep 29, 2026 |
| CVE-2026-102676 | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions | HIGH | 8.3 | Sep 29, 2026 |
| CVE-2026-102675 | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled | HIGH | 7.4 | Sep 29, 2026 |
| CVE-2026-102674 | Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions | HIGH | 8.2 | Sep 29, 2026 |
| CVE-2026-102673 | Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab | HIGH | 8.2 | Sep 29, 2026 |
| CVE-2026-70612 | Electron: Sandboxed iframes can launch external protocol handlers | MEDIUM | 5.4 | Aug 5, 2026 |
| CVE-2026-70611 | Electron: DevTools embedder handler executes arbitrary files via shell open | MEDIUM | 6.9 | Aug 5, 2026 |
| CVE-2026-70610 | Electron: contextBridge object copy honors prototype setters | MEDIUM | 5.4 | Aug 5, 2026 |
| CVE-2026-70609 | Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter | MEDIUM | 5.7 | Aug 5, 2026 |
| CVE-2026-70608 | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path | HIGH | 7.2 | Aug 5, 2026 |
| CVE-2026-70607 | Electron: window.open features string controls some window options considered privileged | MEDIUM | 5.3 | Aug 5, 2026 |
| CVE-2026-70606 | Electron: ProtocolResponse.url reuses the default session cache instead of the registering session | MEDIUM | 5.9 | Aug 5, 2026 |
| CVE-2026-70605 | Electron: HTTP redirect followed into local file loader | MEDIUM | 5.9 | Aug 5, 2026 |
| CVE-2026-70604 | Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads | HIGH | 7.4 | Aug 5, 2026 |
| CVE-2026-70603 | Electron: shell.openPath path validation bypass via embedded null byte | MEDIUM | 6.0 | Aug 5, 2026 |
| CVE-2026-70602 | Electron: Extension tab APIs operate across session boundaries | MEDIUM | 6.6 | Aug 5, 2026 |
| CVE-2026-70601 | Electron: Context isolation bypass via Function.prototype.bind hijack | HIGH | 7.5 | Aug 5, 2026 |
| CVE-2026-70600 | Electron: Cross-origin iframe can position native autofill popup | LOW | 3.1 | Aug 5, 2026 |
| CVE-2026-70599 | Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin | MEDIUM | 5.9 | Aug 5, 2026 |
| CVE-2026-70598 | Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size | LOW | 3.9 | Aug 5, 2026 |
| CVE-2026-70597 | Electron: Parent process code-sign check is spoofable | MEDIUM | 6.3 | Aug 5, 2026 |
| CVE-2026-54257 | Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow | CRITICAL | 9.3 | Jun 23, 2026 |
| CVE-2026-34781 | Electron crashes in clipboard.readImage() on malformed clipboard image data | MEDIUM | 5.0 | Apr 7, 2026 |
| CVE-2026-34765 | Electron named window.open targets not scoped to the opener's browsing context | HIGH | 8.8 | Apr 7, 2026 |
| CVE-2026-34764 | Electron has a use-after-free in offscreen shared texture release() callback | MEDIUM | 5.5 | Apr 6, 2026 |
Showing 1 to 25 of 61 CVEs