Skip to content
RequestGuard Vulnerabilities
Pricing

electron

Build cross platform desktop apps with JavaScript, HTML, and CSS

npm latest 44.4.3 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

44.4.3

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

65 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

65
GHSA-qqvq-6xgj-jw8g high CISA KEV

Electron affected by libvpx's heap buffer overflow in vp8 encoding

Affected range

SEMVER: introduced 0; fixed 22.3.25SEMVER: introduced 24.0.0; fixed 24.8.5SEMVER: introduced 25.0.0; fixed 25.8.4SEMVER: introduced 26.0.0; fixed 26.2.4SEMVER: introduced 27.0.0-alpha.1; fixed 27.0.0-beta.8

Fixed versions: 22.3.25, 24.8.5, 25.8.4, 26.2.4, 27.0.0-beta.8

GHSA-j7hp-h8jx-5ppr high CISA KEV

libwebp: OOB write in BuildHuffmanTable

Affected range

SEMVER: introduced 22.0.0; fixed 22.3.24SEMVER: introduced 24.0.0; fixed 24.8.3SEMVER: introduced 25.0.0; fixed 25.8.1SEMVER: introduced 26.0.0; fixed 26.2.1SEMVER: introduced 27.0.0-beta.1; fixed 27.0.0-beta.2

Fixed versions: 22.3.24, 24.8.3, 25.8.1, 26.2.1, 27.0.0-beta.2

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

Affected range

SEMVER: introduced 42.0.0-alpha.1; fixed 42.0.1SEMVER: introduced 40.0.0-alpha.1; fixed 41.10.3SEMVER: introduced 0; fixed 39.8.10

Fixed versions: 42.0.1, 41.10.3, 39.8.10

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

Affected range

SEMVER: introduced 42.0.0-alpha.1; fixed 42.0.0SEMVER: introduced 41.0.0-alpha.1; fixed 41.4.0SEMVER: introduced 40.0.0-alpha.1; fixed 40.9.3SEMVER: introduced 0; fixed 39.8.10

Fixed versions: 42.0.0, 41.4.0, 40.9.3, 39.8.10

Electron: Context isolation bypass via Function.prototype.bind hijack

Affected range

SEMVER: introduced 0; fixed 39.8.9SEMVER: introduced 40.0.0-alpha.1; fixed 40.9.2SEMVER: introduced 41.0.0-alpha.1; fixed 41.2.2SEMVER: introduced 42.0.0-alpha.1; fixed 42.0.0-beta.5

Fixed versions: 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5

Unpreventable top-level navigation

Affected range

SEMVER: introduced 8.0.0-beta.0; fixed 8.5.1SEMVER: introduced 9.0.0-beta.0; fixed 9.3.0SEMVER: introduced 10.0.0-beta.0; fixed 10.0.1

Fixed versions: 8.5.1, 9.3.0, 10.0.1

Electron: Use-after-free in PowerMonitor on Windows and macOS

Affected range

SEMVER: introduced 0; fixed 38.8.6SEMVER: introduced 39.0.0-alpha.1; fixed 39.8.1SEMVER: introduced 40.0.0-alpha.1; fixed 40.8.0SEMVER: introduced 41.0.0-alpha.1; fixed 41.0.0-beta.8

Fixed versions: 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8

Electron: Use-after-free in offscreen child window paint callback

Affected range

SEMVER: introduced 0; fixed 39.8.1SEMVER: introduced 40.0.0-alpha.1; fixed 40.7.0SEMVER: introduced 41.0.0-alpha.1; fixed 41.0.0

Fixed versions: 39.8.1, 40.7.0, 41.0.0

Electron: Context Isolation bypass via contextBridge VideoFrame transfer

Affected range

SEMVER: introduced 39.0.0-alpha.1; fixed 39.8.0SEMVER: introduced 40.0.0-alpha.1; fixed 40.7.0SEMVER: introduced 41.0.0-alpha.1; fixed 41.0.0-beta.8

Fixed versions: 39.8.0, 40.7.0, 41.0.0-beta.8

Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

Affected range

SEMVER: introduced 0; fixed 38.8.6SEMVER: introduced 39.0.0-alpha.1; fixed 39.8.0SEMVER: introduced 40.0.0-alpha.1; fixed 40.7.0SEMVER: introduced 41.0.0-alpha.1; fixed 41.0.0-beta.8

Fixed versions: 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8

Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

Affected range

SEMVER: introduced 0; fixed 38.8.6SEMVER: introduced 39.0.0-alpha.1; fixed 39.8.0SEMVER: introduced 40.0.0-alpha.1; fixed 40.7.0SEMVER: introduced 41.0.0-alpha.1; fixed 41.0.0-beta.8

Fixed versions: 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8

electron ASAR Integrity bypass by just modifying the content

Affected range

SEMVER: introduced 30.0.0-alpha.1; fixed 30.0.5SEMVER: introduced 31.0.0-alpha.1; fixed 31.0.0-beta.1

Fixed versions: 30.0.5, 31.0.0-beta.1

Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled

Affected range

SEMVER: introduced 22.0.0-beta.1; fixed 22.0.1SEMVER: introduced 23.0.0-alpha.1; fixed 23.0.0-alpha.2

Fixed versions: 22.0.1, 23.0.0-alpha.2

Electron webPreferences vulnerability can be used to perform remote code execution

Affected range

SEMVER: introduced 1.7.0; fixed 1.7.16SEMVER: introduced 1.8.0; fixed 1.8.8SEMVER: introduced 2.0.0; fixed 2.0.8SEMVER: introduced 3.0.0-beta.1; fixed 3.0.0-beta.7

Fixed versions: 1.7.16, 1.8.8, 2.0.8, 3.0.0-beta.7

Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration

Affected range

SEMVER: introduced 1.7.0; fixed 1.7.13SEMVER: introduced 1.8.0; fixed 1.8.4SEMVER: introduced 2.0.0-beta.1; fixed 2.0.0-beta.5

Fixed versions: 1.7.13, 1.8.4, 2.0.0-beta.5

Remote Code Execution in electron

Affected range

SEMVER: introduced 1.7.0; fixed 1.7.11SEMVER: introduced 1.6.0; fixed 1.6.16SEMVER: introduced 1.8.0; fixed 1.8.2-beta.4

Fixed versions: 1.7.11, 1.6.16, 1.8.2-beta.4

ASAR Integrity bypass via filetype confusion in electron

Affected range

SEMVER: introduced 0; fixed 22.3.24SEMVER: introduced 24.0.0-alpha.1; fixed 24.8.3SEMVER: introduced 25.0.0-alpha.1; fixed 25.8.1SEMVER: introduced 26.0.0-alpha.1; fixed 26.2.1SEMVER: introduced 27.0.0-alpha.1; fixed 27.0.0-alpha.7

Fixed versions: 22.3.24, 24.8.3, 25.8.1, 26.2.1, 27.0.0-alpha.7

Show 40 more advisories
GHSA-p7v2-p9m8-qqg7 Electron context isolation bypass via nested unserializable return value
GHSA-7x97-j373-85x5 Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
GHSA-hvf8-h2qh-37m9 IPC messages delivered to the wrong frame in Electron
GHSA-4f78-qhmw-8j8m Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
GHSA-p2rr-rvmm-c5fp Electron: Sandboxed iframes can launch external protocol handlers
GHSA-f2r8-jv7c-xqmp Electron: DevTools embedder handler executes arbitrary files via shell open
GHSA-ff2p-hmqr-hxm4 Electron: contextBridge object copy honors prototype setters
GHSA-v93f-fgjr-hjrj Electron: window.open features string controls some window options considered privileged
GHSA-v64r-4m7r-3mvq Electron: HTTP redirect followed into local file loader
GHSA-r4w5-6pfg-jxp5 Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
GHSA-m55f-7gqj-fr98 Electron: Extension tab APIs operate across session boundaries
GHSA-5c9j-mhmv-5xgx Electron: shell.openPath path validation bypass via embedded null byte
GHSA-9pf5-hg6p-4pwp Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
GHSA-jm7p-cc5g-qwxx Electron: Parent process code-sign check is spoofable
GHSA-mpjm-v997-c4h4 Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
GHSA-6vrv-94jv-crrg Context isolation bypass via Promise in Electron
GHSA-56pc-6jqp-xqj8 Context isolation bypass in Electron
GHSA-f9mq-jph6-9mhm Arbitrary file read via window-open IPC in Electron
GHSA-f3pv-wv63-48x8 Electron: Named window.open targets not scoped to the opener's browsing context
GHSA-4p4r-m79c-wq3v Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
GHSA-3c8v-cfp5-9885 Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
GHSA-5rqw-r77c-jp79 Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
GHSA-xwr5-m59h-vwqr Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
GHSA-xj5x-m3f3-5x3h Electron: Service worker can spoof executeJavaScript IPC replies
GHSA-9w97-2464-8783 Electron: Use-after-free in download save dialog callback
GHSA-r5p7-gp4j-qhrx Electron: Incorrect origin passed to permission request handler for iframe requests
GHSA-mwmh-mq4g-g6gr Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
GHSA-vmqv-hx8q-j7mg Electron has ASAR Integrity Bypass via resource modification
GHSA-6r2x-8pq8-9489 Electron vulnerable to Heap Buffer Overflow in NativeImage
GHSA-p2jh-44qj-pf2v Exfiltration of hashed SMB credentials on Windows via file:// redirect
GHSA-77xc-hjv8-ww97 AutoUpdater module fails to validate certain nested components of the bundle
GHSA-6h98-cf9g-vmg2 Electron vulnerable to URL spoofing via PDFium
GHSA-x8rc-wpg4-grpf Electron: Cross-origin iframe can position native autofill popup
GHSA-pfmc-3mgc-p6fp Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
GHSA-f37v-82c4-4x64 Electron: Crash in clipboard.readImage() on malformed clipboard image data
GHSA-8x5q-pvf5-64mp Electron: Use-after-free in offscreen shared texture release() callback
GHSA-jfqx-fxh3-c62j Electron: Unquoted executable path in app.setLoginItemSettings on Windows
GHSA-9899-m83m-qhpj Electron: USB device selection not validated against filtered device list
GHSA-mq8j-3h7h-p8g7 Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
GHSA-3p22-ghq8-v749 Renderers can obtain access to random bluetooth device without permission in Electron