Cross-Origin Vulnerability in Electron Framework for Desktop Applications
CVE-2026-102675

7.4HIGH

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102675?

A cross-origin vulnerability exists in the Electron framework prior to specified versions due to improper handling of protocol responses. When custom schemes are registered with supportFetchAPI enabled but corsEnabled disabled, responses can potentially remain readable across origins, creating risks for untrusted content loaded within the same session. This vulnerability emphasizes the importance of using appropriate configuration settings when registering protocols, especially in applications that handle sensitive data. Upgrading to the latest versions ensures applications are safeguarded against this issue.

Affected Version(s)

electron < 41.10.6 < 41.10.6

electron >= 42.0.0-alpha.1, < 42.9.2 < 42.0.0-alpha.1, 42.9.2

electron >= 43.0.0-alpha.1, < 43.4.1 < 43.0.0-alpha.1, 43.4.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.