electron is vulnerable to Use After Free
88
High Risk
electron's embedded Chromium DOM can free element attribute storage while batch attribute updates still reference it. Crafted HTML that manipulates element attributes during batch notifications can trigger the use-after-free. Pre-fix versions risk sandboxed arbitrary code execution. The backport uses index-based cloning, stronger attribute batch checks, forbidden event dispatch scopes, and safer slider element construction.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant