CVE-2026-102677
- EPSS 0.09%
- Veröffentlicht 29.09.2026 17:43:26
- Zuletzt bearbeitet 08.10.2026 20:24:30
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the prelo...
CVE-2026-102676
- EPSS 0.45%
- Veröffentlicht 29.09.2026 17:17:07
- Zuletzt bearbeitet 30.09.2026 19:38:27
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even whe...
CVE-2026-102675
- EPSS 0.21%
- Veröffentlicht 29.09.2026 17:17:07
- Zuletzt bearbeitet 30.09.2026 19:38:27
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a...
CVE-2026-102674
- EPSS 0.27%
- Veröffentlicht 29.09.2026 17:17:07
- Zuletzt bearbeitet 30.09.2026 19:38:27
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTM...
CVE-2026-102673
- EPSS 0.15%
- Veröffentlicht 29.09.2026 17:17:07
- Zuletzt bearbeitet 30.09.2026 21:17:04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links usi...
CVE-2026-70612
- EPSS 0.36%
- Veröffentlicht 05.08.2026 17:56:41
- Zuletzt bearbeitet 08.10.2026 13:49:00
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restricti...
CVE-2026-70611
- EPSS 0.13%
- Veröffentlicht 05.08.2026 17:49:09
- Zuletzt bearbeitet 08.10.2026 13:49:43
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it....
CVE-2026-70610
- EPSS 0.38%
- Veröffentlicht 05.08.2026 17:41:03
- Zuletzt bearbeitet 08.10.2026 13:53:12
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacke...
CVE-2026-70609
- EPSS 0.32%
- Veröffentlicht 05.08.2026 17:32:21
- Zuletzt bearbeitet 08.10.2026 13:53:24
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools fro...
CVE-2026-70608
- EPSS 0.26%
- Veröffentlicht 05.08.2026 17:27:15
- Zuletzt bearbeitet 08.10.2026 13:53:39
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenH...