CVE-2026-34765Disclosure(electronjs / electron)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch electronjs electron systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name. If that existing child was created with more permissive webPreferences (via setWindowOpenHandler's overrideBrowserWindowOptions), content loaded by the second renderer inherits those permissions. Apps are only affected if they open multiple top-level windows with differing trust levels and use setWindowOpenHandler to grant child windows elevated webPreferences such as a privileged preload script. Apps that do not elevate child window privileges, or that use a single top-level window, are not affected. Apps that additionally grant nodeIntegration: true or sandbox: false to child windows (contrary to the security recommendations) may be exposed to arbitrary code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
electron

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-08: 2Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34765 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a re… https://www.cve.org/CVERecord?id=CVE-2026-34765

    Post summary

    CVE‑2026‑34765 discloses a vulnerability affecting Electron versions prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0‑alpha.5, with patching implied in later releases.

    00000155
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34765 Cross-Renderer Window Navigation Vulnerability in Electron Prior to 39.8.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34765

    Post summary

    The text notes the existence of CVE‑2026‑34765—a Cross‑Renderer Window Navigation vulnerability affecting Electron before 39.8.5—providing only a link to a vulnerability database entry without additional details.

    0000039
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.2.0node.js-
Appelectronjselectron42.0.0node.js-
Appelectronjselectron42.0.0node.js-
Appelectronjselectron42.0.0node.js-
Appelectronjselectron42.0.0node.js-

Explore more