electron
Build cross platform desktop apps with JavaScript, HTML, and CSS
Security Advisories for electron in npm
Moderate
11 days ago
Electron: DevTools embedder handler executes arbitrary files via shell open
npm
electron
Moderate
11 days ago
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
npm
electron
High
11 days ago
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
npm
electron
Moderate
11 days ago
Electron: window.open features string controls some window options considered privileged
npm
electron
Moderate
11 days ago
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
npm
electron
High
11 days ago
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
npm
electron
Moderate
11 days ago
Electron: shell.openPath path validation bypass via embedded null byte
npm
electron
Moderate
11 days ago
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
npm
electron
Low
11 days ago
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
npm
electron
Critical
2 months ago
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
npm
electron
Low
4 months ago
Electron: Crash in clipboard.readImage() on malformed clipboard image data
npm
electron
Moderate
4 months ago
Electron: Named window.open targets not scoped to the opener's browsing context
npm
electron
Low
4 months ago
Electron: Use-after-free in offscreen shared texture release() callback
npm
electron
High
5 months ago
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
npm
electron
Moderate
5 months ago
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
npm
electron
Moderate
5 months ago
Electron: Incorrect origin passed to permission request handler for iframe requests
npm
electron
Moderate
5 months ago
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
npm
electron
Moderate
5 months ago
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
npm
electron
Moderate
5 months ago
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
npm
electron
High
5 months ago
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
npm
electron
High
5 months ago
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
npm
electron
Low
5 months ago
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
npm
electron
Moderate
5 months ago
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
npm
electron
Low
5 months ago
Electron: USB device selection not validated against filtered device list
npm
electron
High
almost 3 years ago
Electron affected by libvpx's heap buffer overflow in vp8 encoding
npm
electron
Moderate
almost 3 years ago
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
npm
electron
Moderate
almost 3 years ago
Electron context isolation bypass via nested unserializable return value
npm
electron
High
almost 3 years ago
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
npm
electron
Moderate
almost 4 years ago
Exfiltration of hashed SMB credentials on Windows via file:// redirect
npm
electron
Moderate
about 4 years ago
AutoUpdater module fails to validate certain nested components of the bundle
npm
electron
Low
about 4 years ago
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
npm
electron
Low
over 4 years ago
Renderers can obtain access to random bluetooth device without permission in Electron
npm
electron
Moderate
almost 5 years ago
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
npm
electron
High
about 6 years ago
Context isolation bypass via leaked cross-context objects in Electron
npm
electron
High
almost 8 years ago
Electron webPreferences vulnerability can be used to perform remote code execution
npm
electron
High
over 8 years ago
Electron protocol handler browser vulnerable to Command Injection
npm
electron
High
over 8 years ago
Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration
npm
electron