Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

electron — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in electron, with AI-generated Chinese analysis, references, and POCs.

This page serves as a vulnerability aggregation resource for the Electron framework, focusing on general software weaknesses and security advisories. It compiles historical data regarding critical flaws, including remote code execution vulnerabilities, privilege escalation issues, and cross-site scripting weaknesses found in various releases of the application. The dataset covers security incidents from its early development phases through recent stable builds, providing a comprehensive timeline of fixes and patches issued by the maintainers. Readers can use this resource to track specific vendor advisories and understand the evolution of common weakness classes within the project. By reviewing the vulnerability history, developers can better assess the security posture of their own applications built on this technology. The information helps teams identify patterns in how specific types of bugs were addressed over time, offering insights into the project's security response mechanisms. This aggregated view allows for a deeper analysis of risk factors without needing to consult individual commit logs or scattered mailing list posts. It is designed to assist security analysts and engineers in making informed decisions about dependency updates and configuration hardening. The content remains neutral and factual, avoiding promotional language or subjective evaluations of the platform's overall quality. Users are encouraged to cross-reference this summary with official documentation and current CVE databases for the most accurate and timely security guidance.

Vendor: electron

CVE IDTitleCVSSSeverityPublished
CVE-2026-70612 Electron: Sandboxed iframes can launch external protocol handlers CWE-284 5.4 Medium2026-08-05
CVE-2026-70611 Electron: DevTools embedder handler executes arbitrary files via shell open CWE-78 6.9 Medium2026-08-05
CVE-2026-70610 Electron: contextBridge object copy honors prototype setters CWE-1321 5.4 Medium2026-08-05
CVE-2026-70609 Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter CWE-94 5.7 Medium2026-08-05
CVE-2026-70608 Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path CWE-693 7.2 High2026-08-05
CVE-2026-70607 Electron: window.open features string controls some window options considered privileged CWE-20 5.3 Medium2026-08-05
CVE-2026-70606 Electron: ProtocolResponse.url reuses the default session cache instead of the registering session CWE-668 5.9 Medium2026-08-05
CVE-2026-70605 Electron: HTTP redirect followed into local file loader CWE-918 5.9 Medium2026-08-05
CVE-2026-70604 Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads CWE-942 7.4 High2026-08-05
CVE-2026-70603 Electron: shell.openPath path validation bypass via embedded null byte CWE-20 6.0 Medium2026-08-05
CVE-2026-70602 Electron: Extension tab APIs operate across session boundaries CWE-284 6.6 Medium2026-08-05
CVE-2026-70601 Electron: Context isolation bypass via Function.prototype.bind hijack CWE-693 7.5 High2026-08-05
CVE-2026-70600 Electron: Cross-origin iframe can position native autofill popup CWE-1021 3.1 Low2026-08-05
CVE-2026-70599 Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin CWE-346 5.9 Medium2026-08-05
CVE-2026-70598 Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size CWE-125 3.9 Low2026-08-05
CVE-2026-70597 Electron: Parent process code-sign check is spoofable CWE-367 6.3 Medium2026-08-05
CVE-2026-54257 Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow CWE-120--2026-06-23
CVE-2026-34781 Electron crashes in clipboard.readImage() on malformed clipboard image data CWE-476 2.8 Low2026-04-07
CVE-2026-34765 Electron named window.open targets not scoped to the opener's browsing context CWE-668 6.0 Medium2026-04-07
CVE-2026-34764 Electron has a use-after-free in offscreen shared texture release() callback CWE-416 2.3 Low2026-04-06
CVE-2026-34780 Electron: Context Isolation bypass via contextBridge VideoFrame transfer CWE-668 8.4 High2026-04-04
CVE-2026-34779 Electron: AppleScript injection in app.moveToApplicationsFolder on macOS CWE-78 6.5 Medium2026-04-04
CVE-2026-34778 Electron: Service worker can spoof executeJavaScript IPC replies CWE-290 5.9 Medium2026-04-03
CVE-2026-34777 Electron: Incorrect origin passed to permission request handler for iframe requests CWE-346 5.4 Medium2026-04-03
CVE-2026-34776 Electron: Out-of-bounds read in second-instance IPC on macOS and Linux CWE-125 5.3 Medium2026-04-03
CVE-2026-34775 Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes CWE-653 6.8 Medium2026-04-03
CVE-2026-34774 Electron: Use-after-free in offscreen child window paint callback CWE-416 8.1 High2026-04-03
CVE-2026-34773 Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows CWE-20 4.7 Medium2026-04-03
CVE-2026-34772 Electron: Use-after-free in download save dialog callback CWE-416 5.8 Medium2026-04-03
CVE-2026-34771 Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks CWE-416 7.5 High2026-04-03

All 55 known CVE vulnerabilities affecting electron with full Chinese analysis, references, and POCs where available.