electron vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-34775Mediumelectron: Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processesCVE-2026-34774Highelectron: Electron: Use-after-free in offscreen child window paint callbackCVE-2026-34773Mediumelectron: Electron: Registry key path injection in app.setAsDefaultProtocolClient on WindowsCVE-2026-34772Mediumelectron: Electron: Use-after-free in download save dialog callbackCVE-2026-34771Highelectron: Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacksCVE-2026-34770Highelectron: Electron: Use-after-free in PowerMonitor on Windows and macOSCVE-2026-34769Highelectron: Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceCVE-2026-34768Lowelectron: Electron: Unquoted executable path in app.setLoginItemSettings on WindowsCVE-2026-34767Mediumelectron: Electron: HTTP Response Header Injection in custom protocol handlers and webRequestCVE-2026-34766Lowelectron: Electron: USB device selection not validated against filtered device listCVE-2025-55305Mediumelectron: Electron has ASAR Integrity Bypass via resource modificationCVE-2024-46993Mediumelectron: Electron vulnerable to Heap Buffer Overflow in NativeImageCVE-2024-46992Highelectron: electron ASAR Integrity bypass by just modifying the contentCVE-2023-44402Mediumelectron: ASAR Integrity bypass via filetype confusion in electronCVE-2023-5217Highelectron: Electron affected by libvpx's heap buffer overflow in vp8 encodingCVE-2023-4863Highlibwebp-sys2: libwebp: OOB write in BuildHuffmanTableCVE-2023-39956Mediumelectron: Electron vulnerable to out-of-package code execution when launched with arbitrary cwdCVE-2023-29198Mediumelectron: Electron context isolation bypass via nested unserializable return valueCVE-2023-23623Highelectron: Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabledCVE-2022-4135Criticalelectron: Heap buffer overflow in GPUCVE-2022-36077Mediumelectron: Exfiltration of hashed SMB credentials on Windows via file:// redirectCVE-2022-29257Mediumelectron: AutoUpdater module fails to validate certain nested components of the bundleCVE-2022-29247Lowelectron: Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabledCVE-2017-12581Highelectron: Electron vulnerable to remote command executionCVE-2017-1000424MediumElectron: Electron vulnerable to URL spoofing via PDFium

Stop the waste.
Protect your environment with Kodem.