CVE-2026-34780Disclosure(electronjs / electron)

LOWCVSS 6.1 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668CWE-1188CWE-501

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
electron

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-04: 4Technical Details · 2026-04-04: 204-04
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34780 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 … https://www.cve.org/CVERecord?id=CVE-2026-34780 ----- Traducción: CVE-2026-34780 Ele… http://infoflow.cloud`

    Post summary

    A brief alert announcing CVE-2026-34780 for specific Electron releases, linking to the CVE record, with no further exploitation or mitigation details.

    0000041
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34780 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 … https://www.cve.org/CVERecord?id=CVE-2026-34780

    Post summary

    The text announces CVE-2026-34780 for Electron, listing affected versions, but provides no further technical, exploit, patch, or active exploitation details.

    00000171
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34780 - Electron: Context Isolation bypass via contextBridge VideoFrame transfer Intel Report: https://ift.tt/o48bQvl

    Post summary

    The alert announces CVE‑2026‑34780, describing a context isolation bypass in Electron, but does not provide PoC, exploit code, or mitigation steps.

    00000627
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34780 - High Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.... https://www.thehackerwire.com/vulnerability/CVE-2026-34780/ https://t.co/yD0DUXLqqQ

    Post summary

    CVE‑2026‑34780 is a high‑severity vulnerability affecting specific Electron framework versions, disclosed publicly without additional exploit or patch details.

    0000047
    164 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-

Explore more