Node.js Integration Flaw in Electron Framework Enables Elevated Access in Web Workers
CVE-2026-102676

8.3HIGH

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102676?

The Electron framework, designed for building cross-platform desktop applications, contains a vulnerability that allows an untrusted guest in a to enable nodeIntegrationInWorker. This occurs even if the host application has Node.js integration disabled. Consequently, this allows the guest content to create a Node-enabled worker that possesses more privileges than intended by the embedder. Applications that do not utilize the tag or maintain a sandboxed embedder are unaffected. To mitigate this vulnerability, users are advised to update to the fixed versions: 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.

Affected Version(s)

electron < 41.10.6 < 41.10.6

electron >= 42.0.0-alpha.1, < 42.9.2 < 42.0.0-alpha.1, 42.9.2

electron >= 43.0.0-alpha.1, < 43.4.1 < 43.0.0-alpha.1, 43.4.1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.