8.2

CVE-2026-102673

Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerelectron
≫
Produkt electron
Version < 41.10.4
Status affected
Version >= 42.0.0-alpha.1, < 42.5.2
Status affected
Version >= 43.0.0-alpha.1, < 43.0.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.033
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.2 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba
https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69
https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da
https://github.com/electron/electron/pull/52133
https://github.com/electron/electron/releases/tag/v41.10.4
https://github.com/electron/electron/releases/tag/v42.5.2
https://github.com/electron/electron/releases/tag/v43.0.0
https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4