GHSA-9qh4-3jw8-366wHighCVSS 8.3

Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.

Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.

Workarounds

Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.

Fixed Versions

  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6

For more information

If you have any questions or comments about this advisory, email us at [email protected]

🎯 Affected products4

  • npm/electron:< 41.10.6
  • npm/electron:>= 42.0.0-alpha.1, < 42.9.2
  • npm/electron:>= 43.0.0-alpha.1, < 43.4.1
  • npm/electron:>= 44.0.0-alpha.1, < 44.0.0-beta.5

🔗 References (10)