CVE-2026-34781Disclosure(electronjs / electron)

LOWCVSS 3.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode, the resulting null bitmap is passed unchecked to image construction, triggering a controlled abort and crashing the process. Apps are only affected if they call clipboard.readImage(). Apps that do not read images from the clipboard are not affected. This issue does not allow memory corruption or code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
electron

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-08: 2Technical Details · 2026-04-08: 104-08
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-34781 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that… https://www.cve.org/CVERecord?id=CVE-2026-34781

    Post summary

    The post only announces the existence of CVE-2026-34781 and references the CVE record, lacking any detailed technical, exploit, or mitigation information.

    00000166
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34781 Denial of Service in Electron Framework via clipboard.readImage() Prior to 42.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34781

    Post summary

    The entry reports a denial‑of‑service flaw in the Electron framework (versions prior to 42.0.0) caused by the clipboard.readImage() function, without providing PoC code, exploits, or patches.

    0000039
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.2.0node.js-
Appelectronjselectron42.0.0node.js-
Appelectronjselectron42.0.0node.js-
Appelectronjselectron42.0.0node.js-
Appelectronjselectron42.0.0node.js-

Explore more