Launch Week Day 1: Announcing Security Design Review
48 Total advisories
48 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 6.0
npm

CVE-2026-34765

Electron: Named window.open targets not scoped to the opener's browsing context

LOW 2.8
npm

CVE-2026-34781

Electron: Crash in clipboard.readImage() on malformed clipboard image data

LOW 2.3
npm

CVE-2026-34764

Electron: Use-after-free in offscreen shared texture release() callback

MEDIUM 5.9
npm

CVE-2026-34767

Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

HIGH 7.0
npm

CVE-2026-34770

Electron: Use-after-free in PowerMonitor on Windows and macOS

MEDIUM 5.3
npm

CVE-2026-34776

Electron: Out-of-bounds read in second-instance IPC on macOS and Linux

MEDIUM 6.5
npm

CVE-2026-34779

Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

MEDIUM 6.8
npm

CVE-2026-34775

Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

MEDIUM 5.9
npm

CVE-2026-34778

Electron: Service worker can spoof executeJavaScript IPC replies

HIGH 8.1
npm

CVE-2026-34774

Electron: Use-after-free in offscreen child window paint callback

MEDIUM 5.8
npm

CVE-2026-34772

Electron: Use-after-free in download save dialog callback

HIGH 8.3
npm

CVE-2026-34780

Electron: Context Isolation bypass via contextBridge VideoFrame transfer

LOW 3.9
npm

CVE-2026-34768

Electron: Unquoted executable path in app.setLoginItemSettings on Windows

HIGH 7.7
npm

CVE-2026-34769

Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

HIGH 7.5
npm

CVE-2026-34771

Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

MEDIUM 5.4
npm

CVE-2026-34777

Electron: Incorrect origin passed to permission request handler for iframe requests

LOW 3.3
npm

CVE-2026-34766

Electron: USB device selection not validated against filtered device list

MEDIUM 4.7
npm

CVE-2026-34773

Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

HIGH 7.5
npm

CVE-2020-15174

Unpreventable top-level navigation

MEDIUM 5.4
npm

CVE-2020-26272

IPC messages delivered to the wrong frame in Electron

MEDIUM 6.8
npm

CVE-2020-15096

Context isolation bypass via Promise in Electron

MEDIUM 5.6
npm

CVE-2020-15215

Context isolation bypass in Electron

HIGH 7.8
npm

CVE-2020-4076

Context isolation bypass via leaked cross-context objects in Electron

MEDIUM 6.8
npm

CVE-2020-4075

Arbitrary file read via window-open IPC in Electron

MEDIUM 6.8
npm

CVE-2021-39184

Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API

HIGH 7.7
npm

CVE-2020-4077

Context isolation bypass via contextBridge in Electron

HIGH 8.8
crates.io KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

MEDIUM 6.1
npm

CVE-2025-55305

Electron has ASAR Integrity Bypass via resource modification

UNKNOWN
npm

CVE-2024-46993

Electron vulnerable to Heap Buffer Overflow in NativeImage

HIGH 7.8
npm

CVE-2024-46992

electron ASAR Integrity bypass by just modifying the content

MEDIUM 6.1
npm

CVE-2023-44402

ASAR Integrity bypass via filetype confusion in electron

HIGH 8.8
npm KEV

CVE-2023-5217

Electron affected by libvpx's heap buffer overflow in vp8 encoding

MEDIUM 6.1
npm

CVE-2023-39956

Electron vulnerable to out-of-package code execution when launched with arbitrary cwd

MEDIUM 6.0
npm

CVE-2023-29198

Electron context isolation bypass via nested unserializable return value

HIGH 7.5
npm

CVE-2023-23623

Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled

CRITICAL 9.6
npm KEV

CVE-2022-4135

Heap buffer overflow in GPU

MEDIUM 5.4
npm

CVE-2022-36077

Exfiltration of hashed SMB credentials on Windows via file:// redirect

MEDIUM 6.6
npm

CVE-2022-29257

AutoUpdater module fails to validate certain nested components of the bundle

LOW 2.2
npm

CVE-2022-29247

Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled

LOW 3.4
npm

CVE-2022-21718

Renderers can obtain access to random bluetooth device without permission in Electron

HIGH 8.1
npm

CVE-2018-15685

Electron webPreferences vulnerability can be used to perform remote code execution

HIGH 8.1
npm

CVE-2018-1000136

Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration

HIGH 8.8
npm

CVE-2018-1000118

Electron protocol handler browser vulnerable to Command Injection

HIGH 8.8
npm

CVE-2018-1000006

Remote Code Execution in electron

CRITICAL 9.8
npm

CVE-2017-16151

Chromium Remote Code Execution in electron

HIGH 8.1
npm

CVE-2017-12581

Electron vulnerable to remote command execution

MEDIUM 4.3
npm

CVE-2017-1000424

Electron vulnerable to URL spoofing via PDFium

HIGH 7.8
npm

CVE-2016-1202

High severity vulnerability that affects electron

Ready to move

Start Securing

Free, no credit card | First findings in minutes