electron
OSS Librariespackage-ecosystem
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting electron.
- CVE-2026-70612Electron: Sandboxed iframes can launch external protocol handlers5.4
- CVE-2026-70611Electron: DevTools embedder handler executes arbitrary files via shell open6.9
- CVE-2026-70610Electron: contextBridge object copy honors prototype setters5.4
- CVE-2026-70609Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter5.7
- CVE-2026-70608Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path7.2
- CVE-2026-70607Electron: window.open features string controls some window options considered privileged5.3
- CVE-2026-70606Electron: ProtocolResponse.url reuses the default session cache instead of the registering session5.9
- CVE-2026-70605Electron: HTTP redirect followed into local file loader5.9
- CVE-2026-70604Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads7.4
- CVE-2026-70603Electron: shell.openPath path validation bypass via embedded null byte6.0
- CVE-2026-70602Electron: Extension tab APIs operate across session boundaries6.6
- CVE-2026-70601Electron: Context isolation bypass via Function.prototype.bind hijack7.5
- CVE-2026-70600Electron: Cross-origin iframe can position native autofill popup3.1
- CVE-2026-70599Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin5.9
- CVE-2026-70598Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size3.9