Electronjs / Electron
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-34781 | Electron crashes in clipboard.readImage() on malformed clipboard image data | MEDIUM | 5.0 | Apr 7, 2026 |
| CVE-2026-34765 | Electron named window.open targets not scoped to the opener's browsing context | HIGH | 8.8 | Apr 7, 2026 |
| CVE-2026-34764 | Electron has a use-after-free in offscreen shared texture release() callback | MEDIUM | 5.5 | Apr 6, 2026 |
| CVE-2026-34780 | Electron: Context Isolation bypass via contextBridge VideoFrame transfer | HIGH | 8.4 | Apr 4, 2026 |
| CVE-2026-34779 | Electron: AppleScript injection in app.moveToApplicationsFolder on macOS | HIGH | 7.8 | Apr 4, 2026 |
| CVE-2026-34778 | Electron: Service worker can spoof executeJavaScript IPC replies | MEDIUM | 6.5 | Apr 3, 2026 |
| CVE-2026-34777 | Electron: Incorrect origin passed to permission request handler for iframe requests | MEDIUM | 5.4 | Apr 3, 2026 |
| CVE-2026-34776 | Electron: Out-of-bounds read in second-instance IPC on macOS and Linux | MEDIUM | 5.3 | Apr 3, 2026 |
| CVE-2026-34775 | Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes | CRITICAL | 9.8 | Apr 3, 2026 |
| CVE-2026-34774 | Electron: Use-after-free in offscreen child window paint callback | HIGH | 8.1 | Apr 3, 2026 |
| CVE-2026-34773 | Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows | HIGH | 7.5 | Apr 3, 2026 |
| CVE-2026-34772 | Electron: Use-after-free in download save dialog callback | HIGH | 8.8 | Apr 3, 2026 |
| CVE-2026-34771 | Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks | HIGH | 8.8 | Apr 3, 2026 |
| CVE-2026-34770 | Electron: Use-after-free in PowerMonitor on Windows and macOS | HIGH | 8.8 | Apr 3, 2026 |
| CVE-2026-34768 | Electron: Unquoted executable path in app.setLoginItemSettings on Windows | HIGH | 7.8 | Apr 3, 2026 |
| CVE-2026-34767 | Electron: HTTP Response Header Injection in custom protocol handlers and webRequest | MEDIUM | 6.5 | Apr 3, 2026 |
| CVE-2026-34766 | Electron: USB device selection not validated against filtered device list | MEDIUM | 5.4 | Apr 3, 2026 |
| CVE-2026-34769 | Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference | HIGH | 8.8 | Apr 3, 2026 |
| CVE-2023-44402 | ASAR Integrity bypass via filetype confusion in electron | HIGH | 7.0 | Dec 1, 2023 |
| CVE-2023-23623 | Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron | CRITICAL | 9.8 | Sep 6, 2023 |
| CVE-2023-29198 | Context isolation bypass via nested unserializable return value in Electron | HIGH | 8.5 | Sep 6, 2023 |
| CVE-2023-39956 | Electron: Out-of-package code execution when launched with arbitrary cwd | MEDIUM | 6.6 | Sep 6, 2023 |
| CVE-2022-36077 | Electron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirect | HIGH | 7.2 | Nov 8, 2022 |
| CVE-2022-29257 | Electron's AutoUpdater module fails to validate certain nested components of the bundle | HIGH | 7.2 | Jun 13, 2022 |
| CVE-2022-29247 | Exposure of Resource to Wrong Sphere in Electron | CRITICAL | 9.8 | Jun 13, 2022 |
Showing 1 to 25 of 38 CVEs