Cross-Site Scripting Vulnerability in Electron Framework Affects Multiple Versions
CVE-2026-102673

8.2HIGH

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102673?

A vulnerability in the Electron framework enables popups to exploit sandboxed iframes. When links are opened through the OpenURLFromTab navigation path, these popups can inherit the embedding application's origin, allowing untrusted iframes with specific configurations to access sensitive information like cookies and storage, thereby compromising application security. This issue has been addressed in Electron versions 41.10.4, 42.5.2, and 43.0.0, ensuring enhanced protection for applications that properly utilize sandboxing techniques.

Affected Version(s)

electron < 41.10.4 < 41.10.4

electron >= 42.0.0-alpha.1, < 42.5.2 < 42.0.0-alpha.1, 42.5.2

electron >= 43.0.0-alpha.1, < 43.0.0 < 43.0.0-alpha.1, 43.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.