CVE-2026-102674
Received Received - Intake

Electron Sandbox Bypass via Popup Window

Vulnerability report for CVE-2026-102674, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the Electron application's full origin instead of the restricted origin intended by the sandbox. Applications that deny such popups with setWindowOpenHandler are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
electron electron to 41.10.6 (inc)
electron electron to 42.9.2 (inc)
electron electron to 43.4.1 (inc)
electron electron to 44.0.0-beta.5 (inc)
electron electron to 42.9.2 (exc)
electron electron to 43.4.1 (exc)
electron electron to 44.0.0-beta.5 (exc)
electron electron 44.0.0-beta.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Electron applications before versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Windows opened from a sandboxed top-level document did not inherit the sandbox's HTML restrictions. This allowed untrusted content in a sandboxed document to open popups with the application's full origin instead of the restricted sandbox origin.

Detection Guidance

Detection involves checking Electron application versions. Compare installed versions against fixed releases (41.10.6, 42.9.2, 43.4.1, 44.0.0-beta.5). Use commands like 'electron --version' or check package.json for version numbers.

Impact Analysis

An attacker could exploit this to bypass sandbox restrictions, potentially accessing sensitive data or executing unauthorized actions within the application. Users running outdated Electron versions are at risk if the application allows popups from untrusted content.

Mitigation Strategies

Update Electron to the latest patched versions (41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5). If using a sandboxed top-level document, ensure setWindowOpenHandler denies untrusted popups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102674. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart