PT-2026-102710 · Electron · Electron

·

CVE-2026-102675

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 41.10.6 Electron versions prior to 42.9.2 Electron versions prior to 43.4.1 Electron versions prior to 44.0.0-beta.5
Description Responses served through the protocol.registerFileProtocol or protocol.registerHttpProtocol functions for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This occurs when applications expose such a scheme and load untrusted content in the same session. Cross-Origin Resource Sharing (CORS) is a mechanism that restricts web pages from making requests to a different domain than the one that served the web page.
Recommendations Update to version 41.10.6. Update to version 42.9.2. Update to version 43.4.1. Update to version 44.0.0-beta.5. Set corsEnabled to true on the scheme. Avoid loading untrusted content in windows that can reach the registered scheme.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102675
GHSA-J84W-JFHQ-VHVJ

Affected Products

Electron