Code Execution Vulnerability in Electron Framework
CVE-2026-102677

7.8HIGH

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102677?

A vulnerability in the Electron framework, present from versions 42.3.3 up to 42.10.0, 43.5.0, and the 44.0.0-beta.6, allows a compromised renderer to manipulate cached preload code. This enables an attacker to execute arbitrary code with higher privileges when untrusted content is loaded, jeopardizing application security. It is crucial for developers using Electron to upgrade to the patched versions to protect against potential exploitation of this weakness.

Affected Version(s)

electron >= 42.3.3, < 42.10.0 < 42.3.3, 42.10.0

electron >= 43.0.0-beta.1, < 43.5.0 < 43.0.0-beta.1, 43.5.0

electron >= 44.0.0-alpha.1, < 44.0.0-beta.6 < 44.0.0-alpha.1, 44.0.0-beta.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.