CVE-2026-102675
Received Received - Intake

Protocol Scheme Script-Readable Access in Electron

Vulnerability report for CVE-2026-102675, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
electron electron to 41.10.6 (inc)
electron electron to 42.9.2 (inc)
electron electron to 43.4.1 (inc)
electron electron to 44.0.0-beta.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Electron allows cross-origin reads without proper CORS restrictions. It affects applications that register custom schemes with supportFetchAPI enabled but corsEnabled disabled. Attackers could exploit this to read responses cross-origin if the application loads untrusted content in the same session.

Detection Guidance

Detecting this vulnerability requires checking the Electron version in use. Run 'npm list electron' or 'electron --version' in your project directory. If the version is below 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5, the system is vulnerable. Additionally, inspect your application code for custom schemes registered with supportFetchAPI enabled but corsEnabled disabled.

Impact Analysis

If you use an affected Electron version, attackers might access sensitive data from cross-origin responses. This could lead to data leaks or unauthorized information disclosure if untrusted content is loaded in the same session as the vulnerable scheme.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, potentially violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations must ensure proper CORS handling to maintain compliance with these regulations.

Mitigation Strategies

Upgrade Electron to version 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5 or later. Avoid loading untrusted content in sessions that can access custom schemes registered with supportFetchAPI enabled. If possible, set corsEnabled to true for custom schemes, but note this changes behavior rather than fully mitigating the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102675. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart