Node.js Integration Flaw in Electron Framework Enables Elevated Access in Web Workers
CVE-2026-102676
What is CVE-2026-102676?
The Electron framework, designed for building cross-platform desktop applications, contains a vulnerability that allows an untrusted guest in a to enable nodeIntegrationInWorker. This occurs even if the host application has Node.js integration disabled. Consequently, this allows the guest content to create a Node-enabled worker that possesses more privileges than intended by the embedder. Applications that do not utilize the tag or maintain a sandboxed embedder are unaffected. To mitigate this vulnerability, users are advised to update to the fixed versions: 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.
Affected Version(s)
electron < 41.10.6 < 41.10.6
electron >= 42.0.0-alpha.1, < 42.9.2 < 42.0.0-alpha.1, 42.9.2
electron >= 43.0.0-alpha.1, < 43.4.1 < 43.0.0-alpha.1, 43.4.1
