CVE-2026-70603
Received Received - Intake

Null Byte Path Handling Flaw in Electron

Vulnerability report for CVE-2026-70603, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: GitHub, Inc.

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file extension, before passing them to shell.openPath() could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation. Apps are only affected if they pass paths derived from untrusted input to shell.openPath() and rely on string-based validation without a filesystem check. This issue is fixed in versions 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
electron electron to 39.8.6 (exc)
electron electron to 40.9.0 (exc)
electron electron to 41.1.1 (exc)
electron electron to 42.0.0-beta.1 (exc)
electron electron From 42.0.0-alpha.1 (inc) to 42.0.0-beta.1 (inc)
electron electron From 41.0.0-alpha.1 (inc) to 41.1.1 (inc)
electron electron From 40.0.0-alpha.1 (inc) to 40.9.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-158 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Electron framework's shell.openPath() function. It fails to reject file paths containing embedded null bytes, allowing attackers to bypass string-based validation like file extension checks. This could trick an app into opening a different file than intended if untrusted input is passed to shell.openPath() without filesystem checks.

Detection Guidance

To detect this vulnerability, check if your Electron application uses shell.openPath() with untrusted input and performs only string-based validation. Review application logs for file paths containing null bytes. Use commands like grep to search for shell.openPath() calls in your codebase.

Impact Analysis

If you use an affected Electron app that passes untrusted input to shell.openPath() with only string validation, an attacker could open unintended files on your system. This may lead to unauthorized access to sensitive data or execution of malicious files.

Compliance Impact

This vulnerability could lead to unauthorized file access, potentially violating data protection requirements under GDPR or HIPAA if sensitive files are exposed. Compliance may be impacted if the affected app handles regulated data.

Mitigation Strategies

Immediately update Electron to versions 39.8.6, 40.9.0, 41.1.1, or 42.0.0-beta.1 or later. If updating is not possible, ensure all paths passed to shell.openPath() are validated against the filesystem using APIs like fs.existsSync() or fs.stat() before calling shell.openPath(). Reject any path containing null bytes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70603. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart