Vulnerability in Electron Framework Affects External URL Handling
CVE-2026-70612

5.4MEDIUM

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-70612?

The Electron framework prior to certain versions contains a vulnerability that allows external protocol URLs to be opened from web content without considering iframe sandbox restrictions. This loophole can lead to security risks as untrusted content in sandboxed iframes may trigger the launch of OS-registered applications, which could expose users to potential threats. The issue has been addressed in later updates, thus ensuring safer handling of URLs in applications harnessing the Electron framework.

Affected Version(s)

electron < 39.8.8 < 39.8.8

electron >= 40.0.0-alpha.1, < 40.9.0 < 40.0.0-alpha.1, 40.9.0

electron >= 41.0.0-alpha.1, < 41.2.1 < 41.0.0-alpha.1, 41.2.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.