electron
npm71 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting electronpage 2 of 2
- CVE-2026-34778MEDIUMCVSS 6.5EG 6.5fixed in 38.8.6, 39.8.1, 40.8.1 or 41.0.0, by version range2026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal …
- CVE-2026-34779HIGHCVSS 7.8EG 7.8fixed in 38.8.6, 39.8.1, 40.8.0 or 41.0.0-beta.8, by version range2026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path…
- CVE-2026-34780MEDIUMCVSS 6.1EG 6.1fixed in 39.8.0, 40.7.0 or 41.0.0-beta.8, by version range2026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that p…
- CVE-2026-34781LOWCVSS 3.3EG 3.3fixed in 39.8.5, 40.8.5, 41.1.0 or 42.0.0-alpha.5, by version range2026-04-07
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If …
- CVE-2026-54257CRITICALCVSS 9.3EG 9.3fixed in 42.3.32026-06-15
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will cr…
- CVE-2026-70597MEDIUMCVSS 6.3EG 6.3fixed in 39.8.8, 40.9.1, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent…
- CVE-2026-70598LOWCVSS 3.9EG 3.9fixed in 39.8.10, 40.9.0, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validat…
- CVE-2026-70599MEDIUMCVSS 5.9EG 5.9fixed in 39.8.7, 40.9.0, 41.2.0 or 42.0.0-beta.1, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level fr…
- CVE-2026-70600MEDIUMCVSS 4.3EG 4.3fixed in 39.8.8, 40.9.1, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that…
- CVE-2026-70601HIGHCVSS 7.5EG 7.5fixed in 39.8.9, 40.9.2, 41.2.2 or 42.0.0-beta.5, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may b…
- CVE-2026-70602MEDIUMCVSS 6.6EG 6.6fixed in 39.8.8, 40.9.0, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A …
- CVE-2026-70603MEDIUMCVSS 6.0EG 6.0fixed in 42.0.0-beta.1, 41.1.1, 40.9.0 or 39.8.6, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that per…
- CVE-2026-70604HIGHCVSS 7.4EG 7.4fixed in 42.0.0, 41.4.0, 40.9.3 or 39.8.10, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was n…
- CVE-2026-70605MEDIUMCVSS 5.9EG 5.9fixed in 39.8.8, 40.9.1, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which…
- CVE-2026-70606MEDIUMCVSS 5.9EG 5.9fixed in 43.0.0, 42.5.1, 41.9.1 or 40.10.6, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Ele…
- CVE-2026-70607MEDIUMCVSS 5.3EG 5.3fixed in 39.8.8, 40.9.0, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string we…
- CVE-2026-70608HIGHCVSS 7.2EG 7.2fixed in 42.0.1, 41.10.3 or 39.8.10, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger set…
- CVE-2026-70609MEDIUMCVSS 5.7EG 5.7fixed in 39.8.7, 40.9.0, 41.2.0 or 42.0.0-beta.1, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the D…
- CVE-2026-70610MEDIUMCVSS 5.4EG 5.4fixed in 39.8.9, 40.9.2, 41.2.2 or 42.0.0-beta.4, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry…
- CVE-2026-70611MEDIUMCVSS 6.9EG 6.9fixed in 39.8.9, 40.9.2, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than…
- CVE-2026-70612MEDIUMCVSS 5.4EG 5.4fixed in 39.8.8, 40.9.0, 41.2.1 or 42.0.0-beta.3, by version range2026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbo…
Check whether electron is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for electron CVEs against the assets you own.
Book a Demo →