Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102676 | 8.3 HIGH | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restric |
| CVE-2026-102673 | 8.2 HIGH | Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTa |
| CVE-2026-102677 | 7.8 HIGH | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer |
| CVE-2026-102675 | 7.4 HIGH | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled |
No comments yet