electron vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-70612Mediumelectron: Electron: Sandboxed iframes can launch external protocol handlersCVE-2026-70611Mediumelectron: Electron: DevTools embedder handler executes arbitrary files via shell openCVE-2026-70610Mediumelectron: Electron: contextBridge object copy honors prototype settersCVE-2026-70609Mediumelectron: Electron: DevTools JavaScript Injection via Unsanitized Dock State ParameterCVE-2026-70608Highelectron: Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathCVE-2026-70607Mediumelectron: Electron: window.open features string controls some window options considered privilegedCVE-2026-70606Mediumelectron: Electron: ProtocolResponse.url reuses the default session cache instead of the registering sessionCVE-2026-70605Mediumelectron: Electron: HTTP redirect followed into local file loaderCVE-2026-70604Highelectron: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin readsCVE-2026-70602Mediumelectron: Electron: Extension tab APIs operate across session boundariesCVE-2026-70603Mediumelectron: Electron: shell.openPath path validation bypass via embedded null byteCVE-2026-70601Highelectron: Electron: Context isolation bypass via Function.prototype.bind hijackCVE-2026-70600Lowelectron: Electron: Cross-origin iframe can position native autofill popupCVE-2026-70599Mediumelectron: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe OriginCVE-2026-70598Lowelectron: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizeCVE-2026-70597Mediumelectron: Electron: Parent process code-sign check is spoofableCVE-2026-54257Criticalelectron: Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflowCVE-2026-34781Lowelectron: Electron: Crash in clipboard.readImage() on malformed clipboard image dataCVE-2026-34765Mediumelectron: Electron: Named window.open targets not scoped to the opener's browsing contextCVE-2026-34764Lowelectron: Electron: Use-after-free in offscreen shared texture release() callbackCVE-2026-34780Highelectron: Electron: Context Isolation bypass via contextBridge VideoFrame transferCVE-2026-34779Mediumelectron: Electron: AppleScript injection in app.moveToApplicationsFolder on macOSCVE-2026-34778Mediumelectron: Electron: Service worker can spoof executeJavaScript IPC repliesCVE-2026-34777Mediumelectron: Electron: Incorrect origin passed to permission request handler for iframe requestsCVE-2026-34776Mediumelectron: Electron: Out-of-bounds read in second-instance IPC on macOS and Linux

Stop the waste.
Protect your environment with Kodem.