AI description
CVE-2026-102676 describes a vulnerability within the Electron framework, which is used for developing cross-platform desktop applications with JavaScript, HTML, and CSS. Prior to versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron `<webview>` guest could enable `nodeIntegrationInWorker` for its Web Workers. This was possible even if the unsandboxed embedder had Node.js integration disabled, potentially allowing untrusted guest content to create a Node-enabled worker with elevated privileges beyond what the embedder intended. Applications that do not utilize the `<webview>` tag or those that maintain a sandboxed embedder are not affected by this issue. The vulnerability has been addressed in the specified Electron versions.
- Description
- Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 8.3
- Impact score
- 6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-269
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
8
Electronは9月29日、アプリが読み込む信頼できないコンテンツからサンドボックスやオリジン境界、権限制限を突破できる5件の脆弱性を公開した。いずれも深刻度Highで、現時点では実際の悪用や公開PoCは確認さ
@yousukezan
30 Sept 2026
4190 Impressions
1 Retweet
4 Likes
5 Bookmarks
0 Replies
0 Quotes
Five high-severity Electron vulnerabilities, including CVE-2026-102676, CVE-2026-102673 and CVE-2026-102674, weaken sandbox isolation. Update Electron now. #Electron #ElectronJS #CVE2026102676 #AppSecurity #Sandbox #JavaScript #DesktopApps #PatchNow https://t.co/vyUGEaPOAS
@Daily_CyberSec
30 Sept 2026
358 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes