GHSA-9qh4-3jw8-366w

Suggest an improvement
Source
https://github.com/advisories/GHSA-9qh4-3jw8-366w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9qh4-3jw8-366w/GHSA-9qh4-3jw8-366w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9qh4-3jw8-366w
Aliases
Published
2026-09-29T18:02:18Z
Modified
2026-09-29T18:15:04Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
Details

Impact

A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.

Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.

Workarounds

Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.

Fixed Versions

  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Database specific
{
    "cwe_ids":  [
        "CWE-1188",
        "CWE-269"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T18:02:18Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
41.10.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9qh4-3jw8-366w/GHSA-9qh4-3jw8-366w.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
42.0.0-alpha.1
Fixed
42.9.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9qh4-3jw8-366w/GHSA-9qh4-3jw8-366w.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
43.0.0-alpha.1
Fixed
43.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9qh4-3jw8-366w/GHSA-9qh4-3jw8-366w.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
44.0.0-alpha.1
Fixed
44.0.0-beta.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9qh4-3jw8-366w/GHSA-9qh4-3jw8-366w.json"