Intel

AIKIDO-2026-10765

electron is vulnerable to Origin Validation Error

Origin Validation Error Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

65

Medium Risk

This Affects:

JSelectron
39.0.0 - 39.8.9
Fixed in 39.8.10
Are you affected? Scan for Free

TL;DR

Custom protocol handlers registered with fetch API support could accidentally bypass cross-origin controls because scheme loaders skipped the standard CORS gate and exposed readable bodies where only opaque responses were intended. Installer paths could resolve inconsistently across Squirrel stages and mishandle symlink-heavy layouts. Sandbox navigation and offscreen rendering paths received tighter enforcement and bounds checks to reduce bypass and out-of-bounds read classes. Graphics and GPU command-buffer validation plus Skia-related hardening closes integer-trim hazards from upstream rendering code.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Origin Validation Error in versions 39.0.0 - 39.8.9.

How to fix this

Upgrade the electron library to the patch version.