GHSA-j84w-jfhq-vhvj

Suggest an improvement
Source
https://github.com/advisories/GHSA-j84w-jfhq-vhvj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j84w-jfhq-vhvj/GHSA-j84w-jfhq-vhvj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j84w-jfhq-vhvj
Aliases
Published
2026-09-29T18:04:24Z
Modified
2026-09-29T18:15:05Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
Details

Impact

Responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI: true but without corsEnabled: true could be read cross-origin by web content. This completes the fix for CVE-2026-70604.

Apps are only affected if they register such a scheme, serve it through one of those handlers, and load untrusted content. Apps that set corsEnabled: true, or that do not load untrusted content, are not affected.

Workarounds

Set corsEnabled: true on the scheme, or do not load untrusted content in windows that can reach it.

Fixed Versions

  • 44.0.0-beta.5
  • 43.4.1
  • 42.9.2
  • 41.10.6

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Database specific
{
    "cwe_ids":  [
        "CWE-346"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T18:04:24Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
41.10.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j84w-jfhq-vhvj/GHSA-j84w-jfhq-vhvj.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
42.0.0-alpha.1
Fixed
42.9.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j84w-jfhq-vhvj/GHSA-j84w-jfhq-vhvj.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
43.0.0-alpha.1
Fixed
43.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j84w-jfhq-vhvj/GHSA-j84w-jfhq-vhvj.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
44.0.0-alpha.1
Fixed
44.0.0-beta.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j84w-jfhq-vhvj/GHSA-j84w-jfhq-vhvj.json"