Intel

AIKIDO-2026-656516

electron is vulnerable to Incorrect Privilege Assignment

Incorrect Privilege AssignmentGHSA-gr2m-v5gq-v685 Published 3 days ago

82

High Risk

This Affects:

JSelectron
1.0.0 - 41.10.5
Fixed in 41.10.6
42.0.0 - 42.9.1
Fixed in 42.9.2
43.0.0 - 43.4.0
Fixed in 43.4.1
Are you affected? Scan for Free

TL;DR

Windows opened from a sandboxed top-level document do not inherit that document's HTML sandbox restrictions, so content meant to run sandboxed can open a window carrying the app's full origin. This affects apps that render untrusted content in a sandboxed top-level document that allows popups and do not deny them in setWindowOpenHandler. The fix propagates the top-level document's sandbox flags to windows it opens, mirroring the existing fix for sandboxed iframes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you render untrusted content in a sandboxed top-level document that allows popups.

Background info

electron is vulnerable to Incorrect Privilege Assignment in versions 1.0.0 - 41.10.5, 42.0.0 - 42.9.1 and 43.0.0 - 43.4.0.

How to fix this

Upgrade the electron library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform