CVE-2026-34777
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was the top-level page's origin rather than the requesting iframe's origin. Apps that grant permissions based on the origin parameter or webContents.getURL() may inadvertently grant permissions to embedded third-party content. The correct requesting URL remains available via details.requestingUrl. Apps that already check details.requestingUrl are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-346
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34777",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34777",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-06T15:32:48.135022Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "electron",
"product": "electron",
"versions": [
{
"status": "affected",
"version": "< 38.8.6"
},
{
"status": "affected",
"version": ">= 39.0.0-alpha.1, < 39.8.1"
},
{
"status": "affected",
"version": ">= 40.0.0-alpha.1, < 40.8.1"
},
{
"status": "affected",
"version": ">= 41.0.0-alpha.1, < 41.0.0"
}
]
}
]
}
],
"published": "2026-04-04T00:16:18.907",
"references": [
{
"url": "https://github.com/electron/electron/security/advisories/GHSA-r5p7-gp4j-qhrx",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-346"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was the top-level page's origin rather than the requesting iframe's origin. Apps that grant permissions based on the origin parameter or webContents.getURL() may inadvertently grant permissions to embedded third-party content. The correct requesting URL remains available via details.requestingUrl. Apps that already check details.requestingUrl are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0."
},
{
"lang": "es",
"value": "Electron es un framework para escribir aplicaciones de escritorio multiplataforma usando JavaScript, HTML y CSS. Antes de las versiones 38.8.6, 39.8.1, 40.8.1 y 41.0.0, cuando un iframe solicitaba permisos de fullscreen, pointerLock, keyboardLock, openExternal o media, el origen pasado a sesión.setPermissionRequestHandler() era el origen de la página de nivel superior en lugar del origen del iframe solicitante. Las aplicaciones que otorgan permisos basándose en el parámetro de origen o webContents.getURL() pueden otorgar permisos inadvertidamente a contenido de terceros incrustado. La URL solicitante correcta permanece disponible a través de details.requestingUrl. Las aplicaciones que ya verifican details.requestingUrl no se ven afectadas. Este problema ha sido parcheado en las versiones 38.8.6, 39.8.1, 40.8.1 y 41.0.0."
}
],
"lastModified": "2026-07-24T22:10:00.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9CE003A2-03CC-4355-AA17-2CBD204EC6C3",
"versionEndExcluding": "38.8.6"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8F28D187-306E-4C9D-ADED-56DD79B04AF3",
"versionEndExcluding": "39.8.1",
"versionStartIncluding": "39.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A8E19E38-B08F-4075-A564-E14DC3F54078",
"versionEndExcluding": "40.8.1",
"versionStartIncluding": "40.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A20225D6-F435-4D09-962D-B162F521B6AD"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "33712802-EB60-4E9A-83B8-9F2320B70CB4"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9D0A9142-54FE-47BB-9FEB-5E97528E28FE"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9E1D191F-DEAE-4DB3-9822-F31AF9FE3BAC"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "45A8192F-3D2C-4987-9BBE-7ECC3F71965D"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "EEA1A2E5-03DB-46CB-8427-7F31A8A7CE1C"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B2DFCE75-BD3F-4537-B5B8-14097E262EA2"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "BC346E25-EA43-4615-8CDB-16D15D46E4FF"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "FA5B3C00-CAFC-4995-BF35-9920F3039E77"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "3672F3FB-6B5E-40FD-8A92-CB4DD6BC6A93"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9EE4F8AE-21D2-4815-85B7-B7ECCC0D5059"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "D195760C-7DD9-4259-9042-EDE65AEAC1D6"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta7:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B370859F-24D3-4B25-B580-1A5B6DB94BFE"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta8:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7F47CFAE-9744-4B54-B7E4-BB8E4346FDBA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}