Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target=
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102676 | 8.3 HIGH | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restric |
| CVE-2026-102674 | 8.2 HIGH | Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox re |
| CVE-2026-102677 | 7.8 HIGH | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer |
| CVE-2026-102675 | 7.4 HIGH | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled |
No comments yet