{"id":"CVE-2026-102676","title":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Wor…","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-269","CWE-1188"],"vendor":"electron","product":"electron","affected":["electron < 41.10.6","electron >= 42.0.0-alpha.1, < 42.9.2","electron >= 43.0.0-alpha.1, < 43.4.1","electron >= 44.0.0-alpha.1, < 44.0.0-beta.5"],"patched":["electron 41.10.6","electron 42.9.2","electron 43.4.1","electron 44.0.0-beta.5"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T20:17:17.243","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102676","references":[{"url":"https://github.com/electron/electron/commit/6462a2e1dc4e6adffd3b7d9b9be1474c45dcbbe2","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/9a675aef8822bae4088567822969f900b3a37671","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/b3ae0aab5cf81c2ed03d04df1ae8e69ecfab7886","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/cd34f335c8664613db5b6e61ae51e2e1846233ae","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v41.10.6","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v42.9.2","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v43.4.1","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v44.0.0-beta.5","label":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/security/advisories/GHSA-9qh4-3jw8-366w","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-9qh4-3jw8-366w"}],"tags":["nvd","cve.org","ghsa","npm"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-29T19:50:13.282220Z"},"aliases":["GHSA-9qh4-3jw8-366w"],"ecosystem":"npm","ingestedAt":"2026-09-29T17:41:02.206Z","slug":"CVE-2026-102676","body":"## Overview\n\nElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-102676)\n\nAffected packages:\n\n- `electron < 41.10.6`\n- `electron >= 42.0.0-alpha.1, < 42.9.2`\n- `electron >= 43.0.0-alpha.1, < 43.4.1`\n- `electron >= 44.0.0-alpha.1, < 44.0.0-beta.5`\n\nPatched in:\n\n- `electron 41.10.6`\n- `electron 42.9.2`\n- `electron 43.4.1`\n- `electron 44.0.0-beta.5`\n\nSource: https://github.com/advisories/GHSA-9qh4-3jw8-366w","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":45.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}