CVE-2026-34775
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawned in frames configured with nodeIntegrationInWorker: false could still receive Node.js integration. Apps are only affected if they enable nodeIntegrationInWorker. Apps that do not use nodeIntegrationInWorker are not affected. This issue has been patched in versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-653
- Published
- 2026-04-03
- Last modified
- 2026-04-08
Affected products
- electron electron
- electron electron
- electron electron
- electron electron
Weakness type
Related vulnerabilities
- CVE-2026-15366 — A control logic defect in a specific built-in webpage of Kids Mode allows users to view local...
- CVE-2026-71325 — Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
- CVE-2026-62246 — Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
- CVE-2026-65635 — Boruta dynamic client registration allows creation of over-privileged OAuth clients
- CVE-2026-53421 — Apache Syncope: Remote Code Execution via Scripted Connector
- CVE-2026-53405 — Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
- CVE-2026-63071 — Apache Syncope: RCE via Groovy Sandbox bypass
- CVE-2026-15738 — Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller