Skip to main content

Improper Isolation or Compartmentalization in electron

CVE-2026-34775

  • electron
  • org.webjars.npm:electron
Severity High
Score 9.8/10

Summary

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.x prior to 39.8.4, 40.x prior to 40.8.4, and 41.x prior to 41.0.0, the "nodeIntegrationInWorker" webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawned in frames configured with "nodeIntegrationInWorker: false" could still receive Node.js integration. Apps are only affected if they enable "nodeIntegrationInWorker." Apps that do not use nodeIntegrationInWorker are not affected. This issue has been patched in versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-653 - Improper Isolation or Compartmentalization

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Advisory Timeline

  • Published