VendorsElectronjselectronall versions
Vulnerabilities

Electronjs Electron

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2020-4077
Context isolation bypass via contextBridge in Electron
Published 2020-07-07 · Modified
9.9EPSS 0.010
CVE-2017-16151
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.
Published 2018-06-07 · Modified
9.8EPSS 0.027
CVE-2022-29247
Exposure of Resource to Wrong Sphere in Electron
Published 2022-06-13 · Modified
9.8EPSS 0.010
CVE-2023-23623
Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron
Published 2023-09-06 · Modified
9.8EPSS 0.007
CVE-2026-34775
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
Published 2026-04-03 · Analyzed
9.8EPSS 0.004
CVE-2018-1000118
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their browser. This vulnerability appears to have been fixed in Electron 1.8.2-beta.5. This issue is due to an incomplete fix for CVE-2018-1000006, specifically the black list used was not case insensitive allowing an attacker to potentially bypass it.
Published 2018-03-07 · Modified
9.3EPSS 0.024
CVE-2020-4076
Context isolation bypass via leaked cross-context objects in Electron
Published 2020-07-07 · Modified
9.0EPSS 0.004
CVE-2026-34769
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
Published 2026-04-03 · Modified
8.8EPSS 0.004
CVE-2026-34771
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Published 2026-04-03 · Modified
8.8EPSS 0.004
CVE-2026-34765
Electron named window.open targets not scoped to the opener's browsing context
Published 2026-04-07 · Analyzed
8.8EPSS 0.004
CVE-2026-34770
Electron: Use-after-free in PowerMonitor on Windows and macOS
Published 2026-04-03 · Analyzed
8.8EPSS 0.003
CVE-2026-34772
Electron: Use-after-free in download save dialog callback
Published 2026-04-03 · Analyzed
8.8EPSS 0.002
CVE-2021-39184
Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
Published 2021-10-12 · Modified
8.6EPSS 0.011
CVE-2023-29198
Context isolation bypass via nested unserializable return value in Electron
Published 2023-09-06 · Modified
8.5EPSS 0.006
CVE-2026-34780
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
Published 2026-04-04 · Modified
8.3EPSS 0.004
CVE-2018-15685
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
Published 2018-08-23 · Modified
8.11 PoCEPSS 0.104
CVE-2018-1000136
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.
Published 2018-03-23 · Modified
8.1EPSS 0.051
CVE-2026-34774
Electron: Use-after-free in offscreen child window paint callback
Published 2026-04-03 · Modified
8.1EPSS 0.006
CVE-2026-34779
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
Published 2026-04-04 · Analyzed
7.8EPSS 0.002
CVE-2026-34768
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Published 2026-04-03 · Analyzed
7.8EPSS 0.001
CVE-2020-15174
Unpreventable top-level navigation in Electron
Published 2020-10-06 · Modified
7.5EPSS 0.014
CVE-2020-4075
Arbitrary file read via window-open IPC in Electron
Published 2020-07-07 · Modified
7.5EPSS 0.012
CVE-2026-34773
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Published 2026-04-03 · Analyzed
7.5EPSS 0.003
CVE-2022-29257
Electron's AutoUpdater module fails to validate certain nested components of the bundle
Published 2022-06-13 · Modified
7.2EPSS 0.009
CVE-2022-36077
Electron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirect
Published 2022-11-08 · Modified
7.2EPSS 0.006
CVE-2023-44402
ASAR Integrity bypass via filetype confusion in electron
Published 2023-12-01 · Modified
7.0EPSS 0.002
CVE-2020-15096
Context isolation bypass via Promise in Electron
Published 2020-07-07 · Modified
6.8EPSS 0.008
CVE-2020-15215
Context isolation bypass in Electron
Published 2020-10-06 · Modified
6.8EPSS 0.007
CVE-2023-39956
Electron: Out-of-package code execution when launched with arbitrary cwd
Published 2023-09-06 · Modified
6.6EPSS 0.005
CVE-2020-26272
Electron vulnerable to ID collision when routing IPC messages to renderers containing OOPIFs
Published 2021-01-28 · Modified
6.5EPSS 0.017
CVE-2026-34767
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
Published 2026-04-03 · Analyzed
6.5EPSS 0.003
CVE-2026-34778
Electron: Service worker can spoof executeJavaScript IPC replies
Published 2026-04-03 · Analyzed
6.5EPSS 0.001
CVE-2026-34764
Electron has a use-after-free in offscreen shared texture release() callback
Published 2026-04-06 · Analyzed
5.5EPSS 0.001
CVE-2026-34766
Electron: USB device selection not validated against filtered device list
Published 2026-04-03 · Analyzed
5.4EPSS 0.002
CVE-2026-34777
Electron: Incorrect origin passed to permission request handler for iframe requests
Published 2026-04-03 · Analyzed
5.4EPSS 0.001
CVE-2026-34776
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
Published 2026-04-03 · Analyzed
5.3EPSS 0.002
CVE-2022-21718
Renderers can obtain access to random bluetooth device without permission in Electron
Published 2022-03-22 · Modified
5.0EPSS 0.009
CVE-2026-34781
Electron crashes in clipboard.readImage() on malformed clipboard image data
Published 2026-04-07 · Analyzed
3.3EPSS 0.001