8.8
CVE-2026-102677
- EPSS 0.09%
- Veröffentlicht 29.09.2026 17:43:26
- Zuletzt bearbeitet 08.10.2026 20:24:30
- Erkennungen
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatform node.js Version >= 42.3.3 <= 42.10.0
Electronjs ≫ Electron SwPlatform node.js Version >= 43.0.0 < 43.4.2
Electronjs ≫ Electron Version 44.0.0 Update alpha1 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha2 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha3 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha4 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha5 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha6 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha7 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha8 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update alpha9 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta1 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta2 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta3 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta4 SwPlatform node.js
Electronjs ≫ Electron Version 44.0.0 Update beta5 SwPlatform node.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.004 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| security-advisories@github.com | 7.8 | 1.1 | 6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq
https://github.com/electron/electron/pull/52480
https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601
https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3
https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217
https://github.com/electron/electron/releases/tag/v42.10.0
https://github.com/electron/electron/releases/tag/v43.5.0
https://github.com/electron/electron/releases/tag/v44.0.0-beta.6