electron is vulnerable to Origin Validation Error
65
Medium Risk
Custom protocol handlers registered with fetch API support could accidentally bypass cross-origin controls because scheme loaders skipped the standard CORS gate and exposed readable bodies where only opaque responses were intended. Installer paths could resolve inconsistently across Squirrel stages and mishandle symlink-heavy layouts. Sandbox navigation and offscreen rendering paths received tighter enforcement and bounds checks to reduce bypass and out-of-bounds read classes. Graphics and GPU command-buffer validation plus Skia-related hardening closes integer-trim hazards from upstream rendering code.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Origin Validation Error in versions 39.0.0 - 39.8.9.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant