CVEs we hold for Electron
Records whose assigning authority named Electron as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-70608Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathelectron
CVE-2026-70607Electron: window.open features string controls some window options considered privilegedelectron
CVE-2026-70606Electron: ProtocolResponse.url reuses the default session cache instead of the registering sessionelectron
CVE-2026-70604Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin readselectron
CVE-2026-70599Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Originelectron
CVE-2026-70598Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizeelectron
CVE-2026-54673electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in…electron-userland builder-util-runtime
CVE-2026-54672electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`electron-userland app-builder-lib
CVE-2026-54257Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflowelectron
CVE-2026-34777Electron: Incorrect origin passed to permission request handler for iframe requestselectron
CVE-2026-34775Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processeselectron
CVE-2026-34773Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windowselectron
CVE-2026-34771Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbackselectron
CVE-2026-34769Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceelectron
CVE-2026-34767Electron: HTTP Response Header Injection in custom protocol handlers and webRequestelectron
CVE-2026-34765Electron named window.open targets not scoped to the opener's browsing contextelectron
CVE-2024-39698Code Signing Bypass on Windows in electron-updater < 6.3.0-alpha.6electron-userland electron-builder
CVE-2024-29900@electron/packager's build process memory potentially leaked into final executableelectron packager
CVE-2024-27303electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)electron-userland electron-builder
CVE-2023-23623Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electronelectron
CVE-2022-36077Electron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirectelectron
CVE-2022-29257Electron's AutoUpdater module fails to validate certain nested components of the bundleelectron
CVE-2022-21718Renderers can obtain access to random bluetooth device without permission in Electronelectron
CVE-2021-39184Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIelectron
CVE-2020-26272Electron vulnerable to ID collision when routing IPC messages to renderers containing OOPIFselectron
61 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.