Build cross platform desktop apps with JavaScript, HTML, and CSS
96%
Total Score
100
91
100
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-917501 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. electron is vulnerable to Sandbox Bypass in versions 1.3.1 - 41.10.3 and 42.0.0 - 42.5.1. | 1.3.1 - 41.10.342.0.0 - 42.5.1 | Medium |
CVE-2026-70612 electron is vulnerable to Improper Access Control in versions 0.0.0 - 39.8.8, 40.0.0-alpha.1 - 40.9.0, 41.0.0-alpha.1 - 41.2.1 and 42.0.0-alpha.1 - 42.0.0-beta.3. | 0.0.0 - 39.8.840.0.0-alpha.1 - 40.9.041.0.0-alpha.1 - 41.2.1 +1 more | Medium |
CVE-2026-70611 electron is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 39.8.9, 40.0.0-alpha.1 - 40.9.2, 41.0.0-alpha.1 - 41.2.1 and 42.0.0-alpha.1 - 42.0.0-beta.3. | 0.0.0 - 39.8.940.0.0-alpha.1 - 40.9.241.0.0-alpha.1 - 41.2.1 +1 more | Medium |
CVE-2026-70610 electron is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 39.8.9, 40.0.0-alpha.1 - 40.9.2, 41.0.0-alpha.1 - 41.2.2 and 42.0.0-alpha.1 - 42.0.0-beta.4. | 0.0.0 - 39.8.940.0.0-alpha.1 - 40.9.241.0.0-alpha.1 - 41.2.2 +1 more | Medium |
CVE-2026-70609 electron is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 39.8.7, 40.0.0-alpha.1 - 40.9.0, 41.0.0-alpha.1 - 41.2.0 and 42.0.0-alpha.1 - 42.0.0-beta.1. | 0.0.0 - 39.8.740.0.0-alpha.1 - 40.9.041.0.0-alpha.1 - 41.2.0 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@types/node Version ^24.9.0 | — | — |
@electron/get Version ^5.0.0 | — | — |
@electron-internal/extract-zip Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant