A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.
Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.
Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.
44.0.0-beta.543.4.142.9.241.10.6If you have any questions or comments about this advisory, email us at security@electronjs.org
{
"cwe_ids": [
"CWE-1188",
"CWE-269"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T18:02:18Z",
"nvd_published_at": null,
"severity": "HIGH"
}