Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242491
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148636
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vv43-5jgx-7qv8
npm/electron
Electron: Local race condition in Squirrel.Mac update installation on macOS
6 days ago
Fix available
Severity - 6.7 (Medium)
GHSA-hq2x-r82h-9wj4
npm/electron
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
6 days ago
Fix available
Severity - 8.2 (High)
GHSA-gr2m-v5gq-v685
npm/electron
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
6 days ago
Fix available
Severity - 8.2 (High)
GHSA-j84w-jfhq-vhvj
npm/electron
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
6 days ago
Fix available
Severity - 7.4 (High)
GHSA-9qh4-3jw8-366w
npm/electron
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
6 days ago
Fix available
Severity - 8.3 (High)
GHSA-qmv3-fv6v-rmhq
npm/electron
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
6 days ago
Fix available
Severity - 7.8 (High)
MAL-2026-15590
npm/com.db.autobahn.notification-center-electron
Malicious code in com.db.autobahn.notification-center-electron (npm)
30 Aug
No fix available
MAL-2026-15589
npm/autobahn-electron-probe
Malicious code in autobahn-electron-probe (npm)
30 Aug
No fix available
MAL-2026-14266
npm/electron-sessions
Malicious code in electron-sessions (npm)
19 Aug
No fix available
GHSA-p2rr-rvmm-c5fp
npm/electron
Electron: Sandboxed iframes can launch external protocol handlers
05 Aug
Fix available
Severity - 5.4 (Medium)
GHSA-f2r8-jv7c-xqmp
npm/electron
Electron: DevTools embedder handler executes arbitrary files via shell open
05 Aug
Fix available
Severity - 6.9 (Medium)
GHSA-ff2p-hmqr-hxm4
npm/electron
Electron: contextBridge object copy honors prototype setters
05 Aug
Fix available
Severity - 5.4 (Medium)
GHSA-4f78-qhmw-8j8m
npm/electron
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
05 Aug
Fix available
Severity - 5.7 (Medium)
GHSA-9f4c-93c8-jc8g
npm/electron
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
05 Aug
Fix available
Severity - 7.2 (High)
GHSA-v93f-fgjr-hjrj
npm/electron
Electron: window.open features string controls some window options considered privileged
05 Aug
Fix available
Severity - 5.3 (Medium)
GHSA-r4w5-6pfg-jxp5
npm/electron
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
05 Aug
Fix available
Severity - 5.9 (Medium)
Load more...
npm - OSV