Vulnerabilities in electron

55 results
Vexday analysis

Electron apresenta 39 vulnerabilidades catalogadas com apenas 1 crítica, e nenhuma sob exploração ativa conhecida, indicando risco contido. A fraqueza predominante é relacionada a exposição inadequada de funcionalidades (CWE-668), padrão esperado para uma plataforma de execução. Apenas 1 vulnerabilidade publicada nos últimos 90 dias sugere que o risco atual é estável, sem sinais recentes de degradação.

CVE-2026-34779MEDIUMElectron: AppleScript injection in app.moveToApplicationsFolder on macOSEPSS 0.2%CVE-2026-70606MEDIUMElectron: ProtocolResponse.url reuses the default session cache instead of the registering sessionEPSS 0.2%CVE-2026-34781LOWElectron crashes in clipboard.readImage() on malformed clipboard image dataEPSS 0.1%CVE-2026-70599MEDIUMElectron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe OriginEPSS 0.1%CVE-2026-70600LOWElectron: Cross-origin iframe can position native autofill popupEPSS 0.1%CVE-2026-70611MEDIUMElectron: DevTools embedder handler executes arbitrary files via shell openEPSS 0.1%CVE-2026-34768LOWElectron: Unquoted executable path in app.setLoginItemSettings on WindowsEPSS 0.1%CVE-2024-46993MEDIUMElectron Vulnerable to Heap Buffer Overflow in NativeImage::CreateFromPathEPSS 0.1%CVE-2026-34778MEDIUMElectron: Service worker can spoof executeJavaScript IPC repliesEPSS 0.1%CVE-2026-34777MEDIUMElectron: Incorrect origin passed to permission request handler for iframe requestsEPSS 0.1%CVE-2024-46992HIGHElectron ASAR Integrity bypass by just modifying the contentEPSS 0.1%CVE-2026-34764LOWElectron has a use-after-free in offscreen shared texture release() callbackEPSS 0.1%CVE-2026-70598LOWElectron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizeEPSS 0.1%CVE-2026-70603MEDIUMElectron: shell.openPath path validation bypass via embedded null byteEPSS 0.1%CVE-2026-70597MEDIUMElectron: Parent process code-sign check is spoofableEPSS 0.1%