Electron

Electron

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 03.04.2026 23:46:11
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After th...

  • EPSS 0.13%
  • Veröffentlicht 03.04.2026 23:44:55
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path t...

  • EPSS 0.21%
  • Veröffentlicht 03.04.2026 23:43:09
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemes...

  • EPSS 0.16%
  • Veröffentlicht 03.04.2026 23:35:10
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against th...

  • EPSS 0.3%
  • Veröffentlicht 03.04.2026 23:33:55
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be ap...

  • EPSS 0.27%
  • Veröffentlicht 04.09.2025 23:05:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity By...

  • EPSS 0.13%
  • Veröffentlicht 01.07.2025 01:55:51
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a...

  • EPSS 0.11%
  • Veröffentlicht 01.07.2025 01:43:13
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity...

Exploit
  • EPSS 6.69%
  • Veröffentlicht 06.08.2017 02:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a p...