CVE-2026-102676
Received Received - Intake

Node.js Integration Bypass in Electron WebView

Vulnerability report for CVE-2026-102676, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
electron electron to 41.10.6 (exc)
electron electron to 42.9.2 (exc)
electron electron to 43.4.1 (exc)
electron electron to 44.0.0-beta.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Electron applications using the webview tag. A guest in a webview could enable Node.js integration in Web Workers even when the main application had it disabled. This allows untrusted content to create privileged workers with more access than intended. Only applications using webview without sandboxing are affected.

Detection Guidance

To detect this vulnerability, check if your Electron application uses the <webview> tag with an unsandboxed embedder and verify the Electron version. Use commands like 'electron --version' to check the version. If the version is below 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5, the system is vulnerable. Inspect application code for <webview> usage and ensure nodeIntegrationInWorker is not enabled in guest preferences.

Impact Analysis

If you use an affected Electron version with webview enabled and no sandbox, malicious web content could execute arbitrary code on your system with elevated privileges. This could lead to data theft, system compromise, or further network attacks.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements or HIPAA's patient privacy rules. Organizations must patch to maintain compliance.

Mitigation Strategies

Update Electron to versions 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5 or later to address the vulnerability. Ensure applications do not enable the <webview> tag or keep the embedder sandboxed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102676. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart