electron
npm65 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting electronpage 2 of 2
- CVE-2026-70598LOWCVSS 3.9EG 3.9✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validat…
- CVE-2026-70599MEDIUMCVSS 5.9EG 5.9✓ Fixed in 42.0.0-beta.12026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level fr…
- CVE-2026-70600LOWCVSS 3.1EG 3.1✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that…
- CVE-2026-70601HIGHCVSS 7.5EG 7.5✓ Fixed in 42.0.0-beta.52026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may b…
- CVE-2026-70602MEDIUMCVSS 6.6EG 6.6✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A …
- CVE-2026-70603MEDIUMCVSS 6.0EG 6.0✓ Fixed in 39.8.62026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that per…
- CVE-2026-70604HIGHCVSS 7.4EG 7.4✓ Fixed in 39.8.102026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was n…
- CVE-2026-70605MEDIUMCVSS 5.9EG 5.9✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which…
- CVE-2026-70606MEDIUMCVSS 5.9EG 5.9✓ Fixed in 40.10.62026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Ele…
- CVE-2026-70607MEDIUMCVSS 5.3EG 5.3✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string we…
- CVE-2026-70608HIGHCVSS 7.2EG 7.2✓ Fixed in 39.8.102026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger set…
- CVE-2026-70609MEDIUMCVSS 5.7EG 5.7✓ Fixed in 42.0.0-beta.12026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the D…
- CVE-2026-70610MEDIUMCVSS 5.4EG 5.4✓ Fixed in 42.0.0-beta.42026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry…
- CVE-2026-70611MEDIUMCVSS 6.9EG 6.9✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than…
- CVE-2026-70612MEDIUMCVSS 5.4EG 5.4✓ Fixed in 42.0.0-beta.32026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbo…
Check whether electron is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for electron CVEs against the assets you own.
Start Free Scan →