65 Total advisories
65 Vulnerabilities
0 Malware

Dependency scanning

Check whether electron is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.7
npm

CVE-2026-70609

Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

HIGH 7.2
npm

CVE-2026-70608

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

MEDIUM 6.9
npm

CVE-2026-70611

Electron: DevTools embedder handler executes arbitrary files via shell open

MEDIUM 5.4
npm

CVE-2026-70612

Electron: Sandboxed iframes can launch external protocol handlers

MEDIUM 5.4
npm

CVE-2026-70610

Electron: contextBridge object copy honors prototype setters

MEDIUM 5.3
npm

CVE-2026-70607

Electron: window.open features string controls some window options considered privileged

MEDIUM 5.9
npm

CVE-2026-70606

Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

HIGH 7.4
npm

CVE-2026-70604

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

MEDIUM 5.9
npm

CVE-2026-70605

Electron: HTTP redirect followed into local file loader

HIGH 7.5
npm

CVE-2026-70601

Electron: Context isolation bypass via Function.prototype.bind hijack

MEDIUM 6.0
npm

CVE-2026-70603

Electron: shell.openPath path validation bypass via embedded null byte

MEDIUM 6.6
npm

CVE-2026-70602

Electron: Extension tab APIs operate across session boundaries

LOW 3.1
npm

CVE-2026-70600

Electron: Cross-origin iframe can position native autofill popup

MEDIUM 5.9
npm

CVE-2026-70599

Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin

LOW 3.9
npm

CVE-2026-70598

Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size

MEDIUM 6.3
npm

CVE-2026-70597

Electron: Parent process code-sign check is spoofable

UNKNOWN
npm

CVE-2026-54257

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

HIGH 7.8
npm

CVE-2020-4076

Context isolation bypass via leaked cross-context objects in Electron

HIGH 7.7
npm

CVE-2020-4077

Context isolation bypass via contextBridge in Electron

MEDIUM 6.8
npm

CVE-2021-39184

Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API

MEDIUM 6.8
npm

CVE-2020-15096

Context isolation bypass via Promise in Electron

MEDIUM 5.6
npm

CVE-2020-15215

Context isolation bypass in Electron

HIGH 7.5
npm

CVE-2020-15174

Unpreventable top-level navigation

MEDIUM 6.8
npm

CVE-2020-4075

Arbitrary file read via window-open IPC in Electron

HIGH 8.8
crates.io KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

HIGH 8.8
npm KEV

CVE-2023-5217

Electron affected by libvpx's heap buffer overflow in vp8 encoding

MEDIUM 6.0
npm

CVE-2026-34765

Electron: Named window.open targets not scoped to the opener's browsing context

LOW 2.8
npm

CVE-2026-34781

Electron: Crash in clipboard.readImage() on malformed clipboard image data

LOW 2.3
npm

CVE-2026-34764

Electron: Use-after-free in offscreen shared texture release() callback

MEDIUM 5.9
npm

CVE-2026-34767

Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

HIGH 7.0
npm

CVE-2026-34770

Electron: Use-after-free in PowerMonitor on Windows and macOS

MEDIUM 5.3
npm

CVE-2026-34776

Electron: Out-of-bounds read in second-instance IPC on macOS and Linux

MEDIUM 6.5
npm

CVE-2026-34779

Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

MEDIUM 6.8
npm

CVE-2026-34775

Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

MEDIUM 5.9
npm

CVE-2026-34778

Electron: Service worker can spoof executeJavaScript IPC replies

HIGH 8.1
npm

CVE-2026-34774

Electron: Use-after-free in offscreen child window paint callback

MEDIUM 5.8
npm

CVE-2026-34772

Electron: Use-after-free in download save dialog callback

HIGH 8.3
npm

CVE-2026-34780

Electron: Context Isolation bypass via contextBridge VideoFrame transfer

LOW 3.9
npm

CVE-2026-34768

Electron: Unquoted executable path in app.setLoginItemSettings on Windows

HIGH 7.7
npm

CVE-2026-34769

Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

HIGH 7.5
npm

CVE-2026-34771

Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

MEDIUM 5.4
npm

CVE-2026-34777

Electron: Incorrect origin passed to permission request handler for iframe requests

LOW 3.3
npm

CVE-2026-34766

Electron: USB device selection not validated against filtered device list

MEDIUM 4.7
npm

CVE-2026-34773

Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

MEDIUM 5.4
npm

CVE-2020-26272

IPC messages delivered to the wrong frame in Electron

MEDIUM 6.1
npm

CVE-2025-55305

Electron has ASAR Integrity Bypass via resource modification

UNKNOWN
npm

CVE-2024-46993

Electron vulnerable to Heap Buffer Overflow in NativeImage

HIGH 7.8
npm

CVE-2024-46992

electron ASAR Integrity bypass by just modifying the content

MEDIUM 6.1
npm

CVE-2023-44402

ASAR Integrity bypass via filetype confusion in electron

MEDIUM 6.1
npm

CVE-2023-39956

Electron vulnerable to out-of-package code execution when launched with arbitrary cwd

MEDIUM 6.0
npm

CVE-2023-29198

Electron context isolation bypass via nested unserializable return value

HIGH 7.5
npm

CVE-2023-23623

Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled

CRITICAL 9.6
npm KEV

CVE-2022-4135

Heap buffer overflow in GPU

MEDIUM 5.4
npm

CVE-2022-36077

Exfiltration of hashed SMB credentials on Windows via file:// redirect

MEDIUM 6.6
npm

CVE-2022-29257

AutoUpdater module fails to validate certain nested components of the bundle

LOW 2.2
npm

CVE-2022-29247

Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled

LOW 3.4
npm

CVE-2022-21718

Renderers can obtain access to random bluetooth device without permission in Electron

HIGH 8.1
npm

CVE-2018-15685

Electron webPreferences vulnerability can be used to perform remote code execution

HIGH 8.1
npm

CVE-2018-1000136

Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration

HIGH 8.8
npm

CVE-2018-1000118

Electron protocol handler browser vulnerable to Command Injection

HIGH 8.8
npm

CVE-2018-1000006

Remote Code Execution in electron

CRITICAL 9.8
npm

CVE-2017-16151

Chromium Remote Code Execution in electron

HIGH 8.1
npm

CVE-2017-12581

Electron vulnerable to remote command execution

MEDIUM 4.3
npm

CVE-2017-1000424

Electron vulnerable to URL spoofing via PDFium

HIGH 7.8
npm

CVE-2016-1202

High severity vulnerability that affects electron

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes