Dependency scanning
Check whether electron is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-70609
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
CVE-2026-70608
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
CVE-2026-70611
Electron: DevTools embedder handler executes arbitrary files via shell open
CVE-2026-70612
Electron: Sandboxed iframes can launch external protocol handlers
CVE-2026-70610
Electron: contextBridge object copy honors prototype setters
CVE-2026-70607
Electron: window.open features string controls some window options considered privileged
CVE-2026-70606
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
CVE-2026-70604
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
CVE-2026-70605
Electron: HTTP redirect followed into local file loader
CVE-2026-70601
Electron: Context isolation bypass via Function.prototype.bind hijack
CVE-2026-70603
Electron: shell.openPath path validation bypass via embedded null byte
CVE-2026-70602
Electron: Extension tab APIs operate across session boundaries
CVE-2026-70600
Electron: Cross-origin iframe can position native autofill popup
CVE-2026-70599
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
CVE-2026-70598
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
CVE-2026-70597
Electron: Parent process code-sign check is spoofable
CVE-2026-54257
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
CVE-2020-4076
Context isolation bypass via leaked cross-context objects in Electron
CVE-2020-4077
Context isolation bypass via contextBridge in Electron
CVE-2021-39184
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
CVE-2020-15096
Context isolation bypass via Promise in Electron
CVE-2020-15215
Context isolation bypass in Electron
CVE-2020-15174
Unpreventable top-level navigation
CVE-2020-4075
Arbitrary file read via window-open IPC in Electron
CVE-2023-4863
libwebp: OOB write in BuildHuffmanTable
CVE-2023-5217
Electron affected by libvpx's heap buffer overflow in vp8 encoding
CVE-2026-34765
Electron: Named window.open targets not scoped to the opener's browsing context
CVE-2026-34781
Electron: Crash in clipboard.readImage() on malformed clipboard image data
CVE-2026-34764
Electron: Use-after-free in offscreen shared texture release() callback
CVE-2026-34767
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
CVE-2026-34770
Electron: Use-after-free in PowerMonitor on Windows and macOS
CVE-2026-34776
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
CVE-2026-34779
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
CVE-2026-34775
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
CVE-2026-34778
Electron: Service worker can spoof executeJavaScript IPC replies
CVE-2026-34774
Electron: Use-after-free in offscreen child window paint callback
CVE-2026-34772
Electron: Use-after-free in download save dialog callback
CVE-2026-34780
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
CVE-2026-34768
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
CVE-2026-34769
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
CVE-2026-34771
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
CVE-2026-34777
Electron: Incorrect origin passed to permission request handler for iframe requests
CVE-2026-34766
Electron: USB device selection not validated against filtered device list
CVE-2026-34773
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
CVE-2020-26272
IPC messages delivered to the wrong frame in Electron
CVE-2025-55305
Electron has ASAR Integrity Bypass via resource modification
CVE-2024-46993
Electron vulnerable to Heap Buffer Overflow in NativeImage
CVE-2024-46992
electron ASAR Integrity bypass by just modifying the content
CVE-2023-44402
ASAR Integrity bypass via filetype confusion in electron
CVE-2023-39956
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
CVE-2023-29198
Electron context isolation bypass via nested unserializable return value
CVE-2023-23623
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
CVE-2022-4135
Heap buffer overflow in GPU
CVE-2022-36077
Exfiltration of hashed SMB credentials on Windows via file:// redirect
CVE-2022-29257
AutoUpdater module fails to validate certain nested components of the bundle
CVE-2022-29247
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
CVE-2022-21718
Renderers can obtain access to random bluetooth device without permission in Electron
CVE-2018-15685
Electron webPreferences vulnerability can be used to perform remote code execution
CVE-2018-1000136
Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration
CVE-2018-1000118
Electron protocol handler browser vulnerable to Command Injection
CVE-2018-1000006
Remote Code Execution in electron
CVE-2017-16151
Chromium Remote Code Execution in electron
CVE-2017-12581
Electron vulnerable to remote command execution
CVE-2017-1000424
Electron vulnerable to URL spoofing via PDFium
CVE-2016-1202
High severity vulnerability that affects electron
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes