HIGH 7.4 npm

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

GHSA-v3j7-r9gq-3gjw · CVE-2026-70604

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject to CORS enforcement. A page loaded from a remote origin could therefore fetch() or XMLHttpRequest that scheme cross-origin and read the full response body, rather than the read being blocked.

Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. Apps that set corsEnabled: true, or that do not load untrusted content, are not affected.

Workarounds

Set corsEnabled: true on schemes that must enforce CORS, and validate the request Origin in your protocol handler before returning sensitive data.

Fixed Versions

  • 42.0.0
  • 41.4.0
  • 40.9.3
  • 39.8.10

For more information

If you have any questions or comments about this advisory, email Electron at security@electronjs.org

Ready to move

Start Securing

Free, no credit card | First findings in minutes