CVE-2026-102673
Received
Received - Intake
Security Bypass in Electron Framework via Popup Origin
Vulnerability report for CVE-2026-102673, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-29
Last updated on: 2026-09-29
Assigner: GitHub, Inc.
Description
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| electron | electron | to 41.10.4 (inc) |
| electron | electron | to 42.5.2 (inc) |
| electron | electron | to 43.0.0 (inc) |
| electron | electron | to 41.10.4 (exc) |
| electron | electron | From 42.0.0-alpha.1 (inc) to 42.5.2 (exc) |
| electron | electron | From 43.0.0-alpha.1 (inc) to 43.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |