---
id: CVE-2026-102673
title: >-
  Electron is a framework for writing cross-platform desktop applications using
  JavaScript, HTML and CSS
summary: >-
  Electron is a framework for writing cross-platform desktop applications using
  JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened
  from a sandboxed iframe through Electron's OpenURLFromTab navigation path,
  includ…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'
cwe:
  - CWE-346
  - CWE-693
vendor: electron
product: electron
affected:
  - electron < 41.10.4
  - 'electron >= 42.0.0-alpha.1, < 42.5.2'
  - 'electron >= 43.0.0-alpha.1, < 43.0.0'
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T17:17:07.487'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102673'
references:
  - url: >-
      https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba
    label: security-advisories@github.com
  - url: >-
      https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69
    label: security-advisories@github.com
  - url: >-
      https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da
    label: security-advisories@github.com
  - url: 'https://github.com/electron/electron/pull/52133'
    label: security-advisories@github.com
  - url: 'https://github.com/electron/electron/releases/tag/v41.10.4'
    label: security-advisories@github.com
  - url: 'https://github.com/electron/electron/releases/tag/v42.5.2'
    label: security-advisories@github.com
  - url: 'https://github.com/electron/electron/releases/tag/v43.0.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-hq2x-r82h-9wj4'
tags:
  - nvd
  - cve.org
  - ghsa
  - npm
ingestedAt: '2026-09-29T17:41:02.205Z'
aliases:
  - GHSA-hq2x-r82h-9wj4
ecosystem: npm
patched:
  - electron 41.10.4
  - electron 42.5.2
  - electron 43.0.0
---

## Overview

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-102673)

Affected packages:

- `electron < 41.10.4`
- `electron >= 42.0.0-alpha.1, < 42.5.2`
- `electron >= 43.0.0-alpha.1, < 43.0.0`

Patched in:

- `electron 41.10.4`
- `electron 42.5.2`
- `electron 43.0.0`

Source: https://github.com/advisories/GHSA-hq2x-r82h-9wj4
