CVE-2026-34768General(electronjs / electron)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app is installed to a path containing spaces, an attacker with write access to an ancestor directory may be able to cause a different executable to run at login instead of the intended app. On a default Windows install, standard system directories are protected against writes by standard users, so exploitation typically requires a non-standard install location. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
electron

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-04: 304-04
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34768 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, o… https://www.cve.org/CVERecord?id=CVE-2026-34768

    Post summary

    The text reports CVE‑2026‑34768 affecting Electron prior to specific versions but does not provide technical details, PoC, exploit code, or evidence of active exploitation.

    00020339
    57.6K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34768 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, o… https://www.cve.org/CVERecord?id=CVE-2026-34768 ----- Traducción: CVE-2026-34768 Ele… http://infoflow.cloud`

    Post summary

    Announcement of CVE-2026-34768, noting affected Electron versions before 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, with no further exploitation, patch, or technical details provided.

    0000049
    67 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34768 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSetti... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34768

    Post summary

    The note references a CVE in Electron and lists affected versions, but it provides no concrete details on the vulnerability, exploitation, or mitigation.

    0000067
    4.0K followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-

Explore more