vciy

CVEs we hold for Electron

Records whose assigning authority named Electron as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-70612Electron: Sandboxed iframes can launch external protocol handlerselectron
CVE-2026-70611Electron: DevTools embedder handler executes arbitrary files via shell openelectron
CVE-2026-70610Electron: contextBridge object copy honors prototype setterselectron
CVE-2026-70609Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameterelectron
CVE-2026-70608Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathelectron
CVE-2026-70607Electron: window.open features string controls some window options considered privilegedelectron
CVE-2026-70606Electron: ProtocolResponse.url reuses the default session cache instead of the registering sessionelectron
CVE-2026-70605Electron: HTTP redirect followed into local file loaderelectron
CVE-2026-70604Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin readselectron
CVE-2026-70603Electron: shell.openPath path validation bypass via embedded null byteelectron
CVE-2026-70602Electron: Extension tab APIs operate across session boundarieselectron
CVE-2026-70601Electron: Context isolation bypass via Function.prototype.bind hijackelectron
CVE-2026-70600Electron: Cross-origin iframe can position native autofill popupelectron
CVE-2026-70599Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Originelectron
CVE-2026-70598Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizeelectron
CVE-2026-70597Electron: Parent process code-sign check is spoofableelectron
CVE-2026-54673electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in…electron-userland builder-util-runtime
CVE-2026-54672electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`electron-userland app-builder-lib
CVE-2026-54257Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflowelectron
CVE-2026-34781Electron crashes in clipboard.readImage() on malformed clipboard image dataelectron
CVE-2026-34780Electron: Context Isolation bypass via contextBridge VideoFrame transferelectron
CVE-2026-34779Electron: AppleScript injection in app.moveToApplicationsFolder on macOSelectron
CVE-2026-34778Electron: Service worker can spoof executeJavaScript IPC replieselectron
CVE-2026-34777Electron: Incorrect origin passed to permission request handler for iframe requestselectron
CVE-2026-34776Electron: Out-of-bounds read in second-instance IPC on macOS and Linuxelectron
CVE-2026-34775Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processeselectron
CVE-2026-34774Electron: Use-after-free in offscreen child window paint callbackelectron
CVE-2026-34773Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windowselectron
CVE-2026-34772Electron: Use-after-free in download save dialog callbackelectron
CVE-2026-34771Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbackselectron
CVE-2026-34770Electron: Use-after-free in PowerMonitor on Windows and macOSelectron
CVE-2026-34769Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceelectron
CVE-2026-34768Electron: Unquoted executable path in app.setLoginItemSettings on Windowselectron
CVE-2026-34767Electron: HTTP Response Header Injection in custom protocol handlers and webRequestelectron
CVE-2026-34766Electron: USB device selection not validated against filtered device listelectron
CVE-2026-34765Electron named window.open targets not scoped to the opener's browsing contextelectron
CVE-2026-34764Electron has a use-after-free in offscreen shared texture release() callbackelectron
CVE-2025-55305Electron is vulnerable to Code Injection via resource modificationelectron
CVE-2024-46993Electron Vulnerable to Heap Buffer Overflow in NativeImage::CreateFromPathelectron
CVE-2024-46992Electron ASAR Integrity bypass by just modifying the contentelectron
CVE-2024-39698Code Signing Bypass on Windows in electron-updater < 6.3.0-alpha.6electron-userland electron-builder
CVE-2024-29900@electron/packager's build process memory potentially leaked into final executableelectron packager
CVE-2024-27303electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)electron-userland electron-builder
CVE-2024-1648electron-pdf 20.0.0 - Local File Read via Server Side XSSelectron-pdf
CVE-2023-44402ASAR Integrity bypass via filetype confusion in electronelectron
CVE-2023-39956Electron: Out-of-package code execution when launched with arbitrary cwdelectron
CVE-2023-29198Context isolation bypass via nested unserializable return value in Electronelectron
CVE-2023-23623Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electronelectron
CVE-2022-36077Electron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirectelectron
CVE-2022-29257Electron's AutoUpdater module fails to validate certain nested components of the bundleelectron
CVE-2022-29247Exposure of Resource to Wrong Sphere in Electronelectron
CVE-2022-21718Renderers can obtain access to random bluetooth device without permission in Electronelectron
CVE-2021-39184Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIelectron
CVE-2020-4077Context isolation bypass via contextBridge in Electronelectron
CVE-2020-4076Context isolation bypass via leaked cross-context objects in Electronelectron
CVE-2020-4075Arbitrary file read via window-open IPC in Electronelectron
CVE-2020-26272Electron vulnerable to ID collision when routing IPC messages to renderers containing OOPIFselectron
CVE-2020-15215Context isolation bypass in Electronelectron
CVE-2020-15174Unpreventable top-level navigation in Electronelectron
CVE-2020-15096Context isolation bypass via Promise in Electronelectron
CVE-2011-3582no title heldElectron Forums (AEF)

61 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.