PT-2026-68287 · Electron · Electron

CVE-2026-70611

·

Published

2026-08-05

·

Updated

2026-08-06

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 39.8.9 Electron versions prior to 40.9.2 Electron versions prior to 41.2.1 Electron versions prior to 42.0.0-beta.3
Description The DevTools reveal in file manager action could launch a target file instead of simply revealing it. An attacker capable of running scripts within the DevTools frontend, such as through a malicious DevTools extension, could leverage the showItemInFolder handling to execute native code outside the sandbox. This occurs when DevTools is opened for windows exposed to untrusted content or untrusted DevTools extensions.
Recommendations Update to version 39.8.9. Update to version 40.9.2. Update to version 41.2.1. Update to version 42.0.0-beta.3. Do not open DevTools for windows that load untrusted content and avoid loading untrusted DevTools extensions.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70611
GHSA-F2R8-JV7C-XQMP

Affected Products

Electron