CVE-2026-34773Disclosure(electronjs / electron)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch electronjs electron systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\Software\Classes\, potentially hijacking existing protocol handlers. Apps are only affected if they call app.setAsDefaultProtocolClient() with a protocol name derived from external or untrusted input. Apps that use a hardcoded protocol name are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
electron

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-04: 2Patch / Workaround · 2026-04-04: 104-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34773 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windo… https://www.cve.org/CVERecord?id=CVE-2026-34773

    Post summary

    The message announces a CVE affecting Electron, noting the issue existed in specific older releases and is fixed in newer versions, but offers no technical or exploit details.

    00010209
    57.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34773 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windo… https://www.cve.org/CVERecord?id=CVE-2026-34773 ----- Traducción: CVE-2026-34773 Ele… http://infoflow.cloud`

    Post summary

    The tweet simply announces CVE‑2026‑34773 affecting certain Electron framework versions and links to the official CVE record, with no further technical details, exploitation information, or patch notes provided.

    0000041
    67 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-

Explore more