Electronjs

Electron

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 29.09.2026 17:43:26
  • Zuletzt bearbeitet 08.10.2026 20:24:30

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the prelo...

  • EPSS 0.36%
  • Veröffentlicht 05.08.2026 17:56:41
  • Zuletzt bearbeitet 08.10.2026 13:49:00

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restricti...

  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 17:49:09
  • Zuletzt bearbeitet 08.10.2026 13:49:43

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it....

  • EPSS 0.38%
  • Veröffentlicht 05.08.2026 17:41:03
  • Zuletzt bearbeitet 08.10.2026 13:53:12

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacke...

  • EPSS 0.32%
  • Veröffentlicht 05.08.2026 17:32:21
  • Zuletzt bearbeitet 08.10.2026 13:53:24

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools fro...

  • EPSS 0.26%
  • Veröffentlicht 05.08.2026 17:27:15
  • Zuletzt bearbeitet 08.10.2026 13:53:39

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenH...

  • EPSS 0.34%
  • Veröffentlicht 05.08.2026 16:24:11
  • Zuletzt bearbeitet 08.10.2026 13:53:43

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string were applied ...

  • EPSS 0.14%
  • Veröffentlicht 05.08.2026 16:17:04
  • Zuletzt bearbeitet 08.10.2026 13:54:11

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's b...

  • EPSS 0.19%
  • Veröffentlicht 05.08.2026 16:17:04
  • Zuletzt bearbeitet 08.10.2026 13:54:09

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerabl...

  • EPSS 0.16%
  • Veröffentlicht 05.08.2026 16:17:04
  • Zuletzt bearbeitet 08.10.2026 13:54:05

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious o...