CVE-2026-102673
Received Received - Intake

Security Bypass in Electron Framework via Popup Origin

Vulnerability report for CVE-2026-102673, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
electron electron to 41.10.4 (inc)
electron electron to 42.5.2 (inc)
electron electron to 43.0.0 (inc)
electron electron to 41.10.4 (exc)
electron electron From 42.0.0-alpha.1 (inc) to 42.5.2 (exc)
electron electron From 43.0.0-alpha.1 (inc) to 43.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Electron applications before versions 41.10.4, 42.5.2, and 43.0.0. Sandboxed iframes with allow-scripts and allow-popups permissions could open popups inheriting the parent application's full origin, exposing cookies, storage, and scripting capabilities to untrusted content.

Detection Guidance

Check Electron application versions using commands like 'electron --version' or inspect installed packages. Compare against fixed versions 41.10.4, 42.5.2, or 43.0.0. Look for sandboxed iframes embedding untrusted content with allow-scripts and allow-popups attributes.

Impact Analysis

If you use an affected Electron app that embeds untrusted content in sandboxed iframes, attackers could exploit this to steal sensitive data like cookies or session tokens, perform actions on your behalf, or access stored information in the application.

Mitigation Strategies

Update Electron to versions 41.10.4, 42.5.2, or 43.0.0 immediately. Review applications using sandboxed iframes with untrusted content and remove allow-popups if not required. Audit embedded iframes for unnecessary permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102673. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart