CVE-2026-34769General(electronjs / electron)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls. Apps are only affected if they construct webPreferences from external or untrusted input without an allowlist. Apps that use a fixed, hardcoded webPreferences object are not affected. This issue has been patched in versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88CWE-912

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
electron

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-03: 1Mentions · 2026-04-04: 2Mentions · 2026-06-01: 1Technical Details · 2026-04-03: 104-0304-0406-01
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-031
General1
2026-04-042
Disclosure1General1
2026-06-011
Disclosure1
Full discourse4 posts
  • kate! ΘΔ@SeedVEVO
    General

    electron devs keep on taking L 4 CVE's dropped earlier today, all impacting (pretty much) every version that's widely used CVE-2026-34769 CVE-2026-34770 CVE-2026-34771 CVE-2026-34774 respectively, they have the severity of; 7.8, 7, 7.5, and 8.1

    Post summary

    The message announces four CVEs affecting all widely used Electron versions and lists their CVSS severity scores, with no additional technical, exploit, or mitigation details.

    10040120
    705 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34769 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, a… https://www.cve.org/CVERecord?id=CVE-2026-34769

    Post summary

    The post references CVE-2026-34769 impacting certain Electron versions but provides no additional details such as PoC, exploit, active usage, patches, or technical specifics.

    00001643
    57.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Electron, Hidden Functionality via commandLineSwitches, #CVE-2026-34769 (Critical) -DC-Jun2026-54 https://dailycve.com/electron-hidden-functionality-via-commandlineswitches-cve-2026-34769-critical-dc-jun2026-54/

    Post summary

    The entry announces a newly disclosed critical vulnerability in Electron (CVE‑2026‑34769) involving hidden functionality via command‑line switches, but offers no further exploitation, patch, or technical detail.

    0000034
    208 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34769 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, a… https://www.cve.org/CVERecord?id=CVE-2026-34769 ----- Traducción: CVE-2026-34769 Ele… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑34769 impacting Electron releases before 38.8.6, 39.8.0, 40.7.0, and 41.0.0‑beta.8, but offers no deeper technical details, patch information, or exploit evidence.

    0000052
    67 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-

Explore more