Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vv43-5jgx-7qv8
  • npm/electron
Electron: Local race condition in Squirrel.Mac update installation on macOS 6 days ago
  • Fix available
  • Severity - 6.7 (Medium)
GHSA-hq2x-r82h-9wj4
  • npm/electron
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab 6 days ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-gr2m-v5gq-v685
  • npm/electron
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions 6 days ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-j84w-jfhq-vhvj
  • npm/electron
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled 6 days ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-9qh4-3jw8-366w
  • npm/electron
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions 6 days ago
  • Fix available
  • Severity - 8.3 (High)
GHSA-qmv3-fv6v-rmhq
  • npm/electron
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer 6 days ago
  • Fix available
  • Severity - 7.8 (High)
MAL-2026-15590
  • npm/com.db.autobahn.notification-center-electron
Malicious code in com.db.autobahn.notification-center-electron (npm) 30 Aug
  • No fix available
MAL-2026-15589
  • npm/autobahn-electron-probe
Malicious code in autobahn-electron-probe (npm) 30 Aug
  • No fix available
MAL-2026-14266
  • npm/electron-sessions
Malicious code in electron-sessions (npm) 19 Aug
  • No fix available
GHSA-p2rr-rvmm-c5fp
  • npm/electron
Electron: Sandboxed iframes can launch external protocol handlers 05 Aug
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-f2r8-jv7c-xqmp
  • npm/electron
Electron: DevTools embedder handler executes arbitrary files via shell open 05 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-ff2p-hmqr-hxm4
  • npm/electron
Electron: contextBridge object copy honors prototype setters 05 Aug
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-4f78-qhmw-8j8m
  • npm/electron
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter 05 Aug
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-9f4c-93c8-jc8g
  • npm/electron
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path 05 Aug
  • Fix available
  • Severity - 7.2 (High)
GHSA-v93f-fgjr-hjrj
  • npm/electron
Electron: window.open features string controls some window options considered privileged 05 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-r4w5-6pfg-jxp5
  • npm/electron
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session 05 Aug
  • Fix available
  • Severity - 5.9 (Medium)