Vulnerabilities in electron

55 results
Vexday analysis

Electron apresenta 39 vulnerabilidades catalogadas com apenas 1 crítica, e nenhuma sob exploração ativa conhecida, indicando risco contido. A fraqueza predominante é relacionada a exposição inadequada de funcionalidades (CWE-668), padrão esperado para uma plataforma de execução. Apenas 1 vulnerabilidade publicada nos últimos 90 dias sugere que o risco atual é estável, sem sinais recentes de degradação.

CVE-2026-34780HIGHElectron: Context Isolation bypass via contextBridge VideoFrame transferEPSS 0.3%CVE-2026-70609MEDIUMElectron: DevTools JavaScript Injection via Unsanitized Dock State ParameterEPSS 0.3%CVE-2026-34765MEDIUMElectron named window.open targets not scoped to the opener's browsing contextEPSS 0.3%CVE-2026-34769HIGHElectron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceEPSS 0.3%CVE-2026-34775MEDIUMElectron: nodeIntegrationInWorker not correctly scoped in shared renderer processesEPSS 0.3%CVE-2026-34771HIGHElectron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacksEPSS 0.3%CVE-2025-55305MEDIUMElectron is vulnerable to Code Injection via resource modificationEPSS 0.3%CVE-2026-70608HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathEPSS 0.3%CVE-2026-54257CRITICALElectron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflowEPSS 0.3%CVE-2026-34770HIGHElectron: Use-after-free in PowerMonitor on Windows and macOSEPSS 0.2%CVE-2026-34773MEDIUMElectron: Registry key path injection in app.setAsDefaultProtocolClient on WindowsEPSS 0.2%CVE-2026-34776MEDIUMElectron: Out-of-bounds read in second-instance IPC on macOS and LinuxEPSS 0.2%CVE-2026-34767MEDIUMElectron: HTTP Response Header Injection in custom protocol handlers and webRequestEPSS 0.2%CVE-2026-34772MEDIUMElectron: Use-after-free in download save dialog callbackEPSS 0.2%CVE-2023-44402MEDIUMASAR Integrity bypass via filetype confusion in electronEPSS 0.2%CVE-2026-70604HIGHElectron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin readsEPSS 0.2%CVE-2026-70605MEDIUMElectron: HTTP redirect followed into local file loaderEPSS 0.2%CVE-2026-70601HIGHElectron: Context isolation bypass via Function.prototype.bind hijackEPSS 0.2%CVE-2026-34766LOWElectron: USB device selection not validated against filtered device listEPSS 0.2%CVE-2026-70602MEDIUMElectron: Extension tab APIs operate across session boundariesEPSS 0.2%