electron is vulnerable to Incorrect Privilege Assignment
82
High Risk
Windows opened from a sandboxed top-level document do not inherit that document's HTML sandbox restrictions, so content meant to run sandboxed can open a window carrying the app's full origin. This affects apps that render untrusted content in a sandboxed top-level document that allows popups and do not deny them in setWindowOpenHandler. The fix propagates the top-level document's sandbox flags to windows it opens, mirroring the existing fix for sandboxed iframes.
You are affected if you are using a version that falls within the vulnerable range and you render untrusted content in a sandboxed top-level document that allows popups.
electron is vulnerable to Incorrect Privilege Assignment in versions 1.0.0 - 41.10.5, 42.0.0 - 42.9.1 and 43.0.0 - 43.4.0.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.