PT-2026-102710 · Electron · Electron
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Electron versions prior to 41.10.6
Electron versions prior to 42.9.2
Electron versions prior to 43.4.1
Electron versions prior to 44.0.0-beta.5
Description
Responses served through the
protocol.registerFileProtocol or protocol.registerHttpProtocol functions for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This occurs when applications expose such a scheme and load untrusted content in the same session. Cross-Origin Resource Sharing (CORS) is a mechanism that restricts web pages from making requests to a different domain than the one that served the web page.Recommendations
Update to version 41.10.6.
Update to version 42.9.2.
Update to version 43.4.1.
Update to version 44.0.0-beta.5.
Set
corsEnabled to true on the scheme.
Avoid loading untrusted content in windows that can reach the registered scheme.Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Electron