CVE-2026-34765
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name.
Leer descripción completaMostrar menos
If that existing child was created with more permissive webPreferences (via setWindowOpenHandler's overrideBrowserWindowOptions), content loaded by the second renderer inherits those permissions. Apps are only affected if they open multiple top-level windows with differing trust levels and use setWindowOpenHandler to grant child windows elevated webPreferences such as a privileged preload script. Apps that do not elevate child window privileges, or that use a single top-level window, are not affected. Apps that additionally grant nodeIntegration: true or sandbox: false to child windows (contrary to the security recommendations) may be exposed to arbitrary code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-668
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34765",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34765",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-09T03:56:10.527333Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.7,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "electron",
"product": "electron",
"versions": [
{
"status": "affected",
"version": "< 39.8.5"
},
{
"status": "affected",
"version": ">= 40.0.0-alpha.1, < 40.8.5"
},
{
"status": "affected",
"version": ">= 41.0.0-alpha.1, < 41.1.0"
},
{
"status": "affected",
"version": ">= 42.0.0-alpha.1, < 42.0.0-alpha.5"
}
]
}
]
}
],
"published": "2026-04-07T22:16:22.960",
"references": [
{
"url": "https://github.com/electron/electron/security/advisories/GHSA-f3pv-wv63-48x8",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-668"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name. If that existing child was created with more permissive webPreferences (via setWindowOpenHandler's overrideBrowserWindowOptions), content loaded by the second renderer inherits those permissions. Apps are only affected if they open multiple top-level windows with differing trust levels and use setWindowOpenHandler to grant child windows elevated webPreferences such as a privileged preload script. Apps that do not elevate child window privileges, or that use a single top-level window, are not affected. Apps that additionally grant nodeIntegration: true or sandbox: false to child windows (contrary to the security recommendations) may be exposed to arbitrary code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5."
},
{
"lang": "es",
"value": "Electron es un framework para escribir aplicaciones de escritorio multiplataforma usando JavaScript, HTML y CSS. Antes de 39.8.5, 40.8.5, 41.1.0 y 42.0.0-alpha.5, cuando un renderizador llama a window.open() con un nombre de destino, Electron no delimitaba correctamente la búsqueda de la ventana con nombre al grupo de contexto de navegación del abridor. Un renderizador podía navegar una ventana secundaria existente que fue abierta por un renderizador diferente y no relacionado si ambos usaban el mismo nombre de destino. Si esa ventana secundaria existente fue creada con webPreferences más permisivas (a través de overrideBrowserWindowOptions de setWindowOpenHandler), el contenido cargado por el segundo renderizador hereda esos permisos. Las aplicaciones solo se ven afectadas si abren múltiples ventanas de nivel superior con diferentes niveles de confianza y usan setWindowOpenHandler para otorgar a las ventanas secundarias webPreferences elevadas, como un script de precarga privilegiado. Las aplicaciones que no elevan los privilegios de las ventanas secundarias, o que usan una única ventana de nivel superior, no se ven afectadas. Las aplicaciones que además otorgan nodeIntegration: true o sandbox: false a las ventanas secundarias (contrario a las recomendaciones de seguridad) pueden estar expuestas a ejecución de código arbitrario. Esta vulnerabilidad está corregida en 39.8.5, 40.8.5, 41.1.0 y 42.0.0-alpha.5."
}
],
"lastModified": "2026-07-24T22:10:00.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "239C939D-31F6-414C-AF8A-385ADA0F2A17",
"versionEndIncluding": "39.8.4"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8190FCCE-AFCA-4D8C-BF8B-C8A3996B0D9D",
"versionEndIncluding": "40.8.4",
"versionStartIncluding": "40.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A87A2631-72BF-432E-B014-AEFE45CB9BAE",
"versionEndExcluding": "41.1.0",
"versionStartIncluding": "41.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.2.0:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "AE2BDFE9-435B-4E7A-9785-0805EE1AED4E"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:42.0.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "498062D8-5C83-4FC2-A04B-94F3228B2BED"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:42.0.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A272F9F4-AB62-407C-B1A8-18586A474C19"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:42.0.0:alpha3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "BF49E260-9653-4D26-8B6C-C6FAFE697F5A"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:42.0.0:alpha4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "2F3B609A-0CA5-4E8C-865E-CF79B6B0CCCC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}