8.8

CVE-2026-102677

Electron: Sandboxed preload code cache can be poisoned by a compromised renderer

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatform node.js Version >= 42.3.3 <= 42.10.0
Electronjs ≫ Electron SwPlatform node.js Version >= 43.0.0 < 43.4.2
Electronjs ≫ Electron Version 44.0.0 Update alpha1 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha2 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha3 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha4 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha5 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha6 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha7 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha8 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha9 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta1 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta2 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta3 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta4 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta5 SwPlatform node.js
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.004
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
security-advisories@github.com 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq
Vendor Advisory
https://github.com/electron/electron/pull/52480
Patch
Issue Tracking
https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601
Patch
https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3
Patch
https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217
Patch
https://github.com/electron/electron/releases/tag/v42.10.0
Release Notes
https://github.com/electron/electron/releases/tag/v43.5.0
Release Notes
https://github.com/electron/electron/releases/tag/v44.0.0-beta.6
Release Notes