8.2
CVE-2026-102673
- EPSS 0.15%
- Veröffentlicht 29.09.2026 17:17:07
- Zuletzt bearbeitet 30.09.2026 21:17:04
- Erkennungen
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerelectron
≫
Produkt
electron
Version
< 41.10.4
Status
affected
Version
>= 42.0.0-alpha.1, < 42.5.2
Status
affected
Version
>= 43.0.0-alpha.1, < 43.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.033 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.2 | 2.8 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CWE-693 Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba
https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69
https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da
https://github.com/electron/electron/pull/52133
https://github.com/electron/electron/releases/tag/v41.10.4
https://github.com/electron/electron/releases/tag/v42.5.2
https://github.com/electron/electron/releases/tag/v43.0.0
https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4