GHSA-gr2m-v5gq-v685HighCVSS 8.2

Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Windows opened from a sandboxed top-level document did not inherit that document's HTML sandbox restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes.

Apps are only affected if they render untrusted content in a sandboxed top-level document that allows popups. Apps that deny popups from untrusted content with setWindowOpenHandler are not affected.

Workarounds

Return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content.

Fixed Versions

  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6

For more information

If you have any questions or comments about this advisory, email us at [email protected]

🎯 Affected products4

  • npm/electron:< 41.10.6
  • npm/electron:>= 42.0.0-alpha.1, < 42.9.2
  • npm/electron:>= 43.0.0-alpha.1, < 43.4.1
  • npm/electron:>= 44.0.0-alpha.1, < 44.0.0-beta.5

🔗 References (10)