PT-2026-102685 · Electron · Electron

·

CVE-2026-102674

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 41.10.6 Electron versions prior to 42.9.2 Electron versions prior to 43.4.1 Electron versions prior to 44.0.0-beta.5
Description Windows opened from a sandboxed top-level document do not inherit the active HTML sandbox restrictions of that document. This allows untrusted content permitted to open popups to create a new window with the full origin of the Electron application instead of the restricted origin intended by the sandbox. This issue does not affect applications that deny such popups using the setWindowOpenHandler function.
Recommendations Update to version 41.10.6. Update to version 42.9.2. Update to version 43.4.1. Update to version 44.0.0-beta.5. As a temporary workaround, return { action: 'deny' } from the setWindowOpenHandler function for windows opened by untrusted content.

Exploit

Fix

Protection Mechanism Failure

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102674
GHSA-GR2M-V5GQ-V685

Affected Products

Electron