GHSA-jm7p-cc5g-qwxx

Suggest an improvement
Source
https://github.com/advisories/GHSA-jm7p-cc5g-qwxx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jm7p-cc5g-qwxx/GHSA-jm7p-cc5g-qwxx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jm7p-cc5g-qwxx
Aliases
Published
2026-08-05T15:21:22Z
Modified
2026-08-05T15:41:04Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Electron: Parent process code-sign check is spoofable
Details

Impact

On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting ELECTRON_RUN_AS_NODE and NODE_OPTIONS to same-signed parents rely on this check; a local attacker could bypass it and run their own code inside the signed app, inheriting its TCC permissions and keychain access.

Apps are only affected if they enable those macOS fuse-based restrictions. Apps that do not enable them are not affected.

Workarounds

There are no app side workarounds, you must update to a patched version of Electron.

Fixed Versions

  • 42.0.0-beta.3
  • 41.2.1
  • 40.9.0
  • 39.8.8

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Database specific
{
    "cwe_ids":  [
        "CWE-367"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-05T15:21:22Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
39.8.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jm7p-cc5g-qwxx/GHSA-jm7p-cc5g-qwxx.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
40.0.0-alpha.1
Fixed
40.9.1

Database specific

last_known_affected_version_range
"< 40.9.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jm7p-cc5g-qwxx/GHSA-jm7p-cc5g-qwxx.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
41.0.0-alpha.1
Fixed
41.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jm7p-cc5g-qwxx/GHSA-jm7p-cc5g-qwxx.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
42.0.0-alpha.1
Fixed
42.0.0-beta.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jm7p-cc5g-qwxx/GHSA-jm7p-cc5g-qwxx.json"