PatchSiren

Electronjs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Electronjs CVE published 2026-04-04

CVE-2026-34779

The Electron framework, used for building cross-platform desktop applications, had a vulnerability prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8. On macOS, the app.moveToApplicationsFolder() function used an AppleScript fallback path that did not properly handle certain characters in the application bundle path. This could lead to arbitrary AppleScript execution if a user accepted the move-t [truncated]

MEDIUM Electronjs CVE published 2026-04-04

CVE-2026-34778

CVE-2026-34778 is a medium-severity vulnerability in Electron, a framework for building cross-platform desktop applications, allowing service workers to spoof reply messages on the internal IPC channel. This issue affects applications that have service workers registered and use the result of webContents.executeJavaScript() or webFrameMain.executeJavaScript() in security-sensitive decisions. The vulnerabi [truncated]

MEDIUM Electronjs CVE published 2026-04-04

CVE-2026-34776

An out-of-bounds heap read issue was found in Electron prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0. This issue affects applications that call app.requestSingleInstanceLock() on macOS and Linux. The vulnerability could allow leaked memory to be delivered to the app's second-instance event handler. The issue has a CVSS score of 5.3 and a severity of MEDIUM.

MEDIUM Electronjs CVE published 2026-04-04

CVE-2026-34775

The CVE record for CVE-2026-34775 was published on 2026-04-04T00:16:18.597Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. Specifically, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations prior to versions 38.8.6 [truncated]

MEDIUM Electronjs CVE published 2026-04-04

CVE-2026-34772

A use-after-free vulnerability exists in Electron, a framework for writing cross-platform desktop applications, prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8. The vulnerability occurs when a session is torn down while a native save-file dialog is open for a download, and dismissing the dialog dereferences freed memory, which may lead to a crash or memory corruption. Apps that do not destroy [truncated]

HIGH Electronjs CVE published 2026-04-04

CVE-2026-34770

CVE-2026-34770 is a high-severity use-after-free vulnerability in Electron, a framework for building cross-platform desktop applications. The vulnerability exists in the powerMonitor module and may allow attackers to cause a crash or memory corruption. Electron versions prior to 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8 are affected. This vulnerability is not directly renderer-controllable. The issue aris [truncated]

HIGH Electronjs CVE published 2026-04-04

CVE-2026-34769

An undocumented webPreference named commandLineSwitches in Electron allowed arbitrary Chromium switches to be appended to the renderer process command line. Applications that construct webPreferences by spreading untrusted configuration objects—without an allowlist—could inadvertently let an attacker inject switches that disable renderer sandboxing or web security controls. This is a configuration-injecti [truncated]

LOW Electronjs CVE published 2026-04-04

CVE-2026-34768

The Electron framework for cross-platform desktop applications had a vulnerability prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8. On Windows, setting login item settings with openAtLogin: true could write the executable path to the Run registry key without proper quoting. This could allow an attacker with write access to an ancestor directory to potentially run a different executable at logi [truncated]