PT-2026-68287 · Electron · Electron
CVE-2026-70611
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v3.1
6.9
Medium
| Vector | AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Electron versions prior to 39.8.9
Electron versions prior to 40.9.2
Electron versions prior to 41.2.1
Electron versions prior to 42.0.0-beta.3
Description
The DevTools reveal in file manager action could launch a target file instead of simply revealing it. An attacker capable of running scripts within the DevTools frontend, such as through a malicious DevTools extension, could leverage the
showItemInFolder handling to execute native code outside the sandbox. This occurs when DevTools is opened for windows exposed to untrusted content or untrusted DevTools extensions.Recommendations
Update to version 39.8.9.
Update to version 40.9.2.
Update to version 41.2.1.
Update to version 42.0.0-beta.3.
Do not open DevTools for windows that load untrusted content and avoid loading untrusted DevTools extensions.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Electron