Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

electron — Vulnerabilities & Security Advisories 60

Browse all 60 CVE security advisories affecting electron. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Electron is an open-source framework enabling developers to build cross-platform desktop applications using web technologies like HTML, CSS, and JavaScript. By embedding the Chromium engine and Node.js runtime, it allows web code to interact directly with the operating system, creating a significant attack surface. Historically, vulnerabilities within this architecture frequently lead to Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from improper handling of IPC channels or insecure default configurations. With 38 recorded CVEs, the framework has faced scrutiny regarding privilege escalation risks when applications fail to properly sandbox web content. While not inherently malicious, the complexity of integrating web and native APIs has resulted in notable security incidents where attackers exploited these interfaces to gain unauthorized system access. Developers must rigorously enforce security policies to mitigate these inherent risks associated with the hybrid nature of Electron-based software.

Found 59 results / 60 Clear Filters
Top products by electron: electron packager
CVE ID Title CVSS Severity Published
CVE-2026-34775 Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes — electron CWE-653 6.8 Medium 2026-04-03
CVE-2026-34774 Electron: Use-after-free in offscreen child window paint callback — electron CWE-416 8.1 High 2026-04-03
CVE-2026-34773 Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows — electron CWE-20 4.7 Medium 2026-04-03
CVE-2026-34772 Electron: Use-after-free in download save dialog callback — electron CWE-416 5.8 Medium 2026-04-03
CVE-2026-34771 Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks — electron CWE-416 7.5 High 2026-04-03
CVE-2026-34770 Electron: Use-after-free in PowerMonitor on Windows and macOS — electron CWE-416 7.0 High 2026-04-03
CVE-2026-34768 Electron: Unquoted executable path in app.setLoginItemSettings on Windows — electron CWE-428 3.9 Low 2026-04-03
CVE-2026-34767 Electron: HTTP Response Header Injection in custom protocol handlers and webRequest — electron CWE-74 5.9 Medium 2026-04-03
CVE-2026-34766 Electron: USB device selection not validated against filtered device list — electron CWE-862 3.3 Low 2026-04-03
CVE-2026-34769 Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference — electron CWE-88 7.8 High 2026-04-03
CVE-2025-55305 Electron is vulnerable to Code Injection via resource modification — electron CWE-94 6.1 Medium 2025-09-04
CVE-2024-46993 Electron Vulnerable to Heap Buffer Overflow in NativeImage::CreateFromPath — electron CWE-122 8.0AI High AI 2025-07-01
CVE-2024-46992 Electron ASAR Integrity bypass by just modifying the content — electron CWE-354 7.8 High 2025-07-01
CVE-2023-44402 ASAR Integrity bypass via filetype confusion in electron — electron CWE-345 6.1 Medium 2023-12-01
CVE-2023-23623 Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron — electron CWE-670 7.5 High 2023-09-06
CVE-2023-29198 Context isolation bypass via nested unserializable return value in Electron — electron CWE-754 6.0 Medium 2023-09-06
CVE-2023-39956 Electron: Out-of-package code execution when launched with arbitrary cwd — electron CWE-94 6.1 Medium 2023-09-06
CVE-2022-36077 Electron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirect — electron CWE-522 7.2 High 2022-11-08
CVE-2022-29257 Electron's AutoUpdater module fails to validate certain nested components of the bundle — electron CWE-20 6.6 Medium 2022-06-13
CVE-2022-29247 Exposure of Resource to Wrong Sphere in Electron — electron CWE-668 2.2 Low 2022-06-13
CVE-2022-21718 Renderers can obtain access to random bluetooth device without permission in Electron — electron CWE-668 3.4 Low 2022-03-22
CVE-2021-39184 Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API — electron CWE-668 6.8 Medium 2021-10-12
CVE-2020-26272 Electron vulnerable to ID collision when routing IPC messages to renderers containing OOPIFs — electron CWE-668 5.4 Medium 2021-01-28
CVE-2020-15215 Context isolation bypass in Electron — electron CWE-693 5.6 Medium 2020-10-06
CVE-2020-15174 Unpreventable top-level navigation in Electron — electron CWE-693 7.5 High 2020-10-06
CVE-2020-15096 Context isolation bypass via Promise in Electron — electron CWE-501 6.8 Medium 2020-07-07
CVE-2020-4075 Arbitrary file read via window-open IPC in Electron — electron CWE-552 6.8 Medium 2020-07-07
CVE-2020-4076 Context isolation bypass via leaked cross-context objects in Electron — electron CWE-501 7.8 High 2020-07-07
CVE-2020-4077 Context isolation bypass via contextBridge in Electron — electron CWE-501 7.7 High 2020-07-07

This page lists every published CVE security advisory associated with electron. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.