Sandboxed Document Vulnerability in Electron Framework
CVE-2026-102674

8.2HIGH

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102674?

The Electron framework allows the creation of cross-platform desktop applications using web technologies. A vulnerability existed in earlier versions of Electron, where windows opened from a sandboxed top-level document did not inherit the expected security restrictions of that document. This loophole enabled untrusted content in the sandboxed document to potentially open new windows with access to the full origin of the Electron application instead of being confined to the intended restricted origin. Applications that effectively manage popup behavior using setWindowOpenHandler were not affected by this issue. The flaw was addressed in specified newer versions of the framework.

Affected Version(s)

electron < 41.10.6 < 41.10.6

electron >= 42.0.0-alpha.1, < 42.9.2 < 42.0.0-alpha.1, 42.9.2

electron >= 43.0.0-alpha.1, < 43.4.1 < 43.0.0-alpha.1, 43.4.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.