CVE-2026-70609Medium· 5.7▾ SunlitElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.4%
Last analysed / modified upstream
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js, including when untrusted input reaches the mode argument of openDevTools() or untrusted content calls openDevTools() on a webview it embeds. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
electron < 39.8.7electron >= 40.0.0-alpha.1, < 40.9.0electron >= 41.0.0-alpha.1, < 41.2.0electron >= 42.0.0-alpha.1, < 42.0.0-beta.1Patched in:
electron 39.8.7electron 40.9.0electron 41.2.0electron 42.0.0-beta.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70612Medium· 5.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70607Medium· 5.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70608High· 7.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70610Medium· 5.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70611Medium· 6.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70603Medium· 6.0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS