Time-of-check Time-of-use (TOCTOU) Race Condition Affecting org.webjars.npm:electron package, versions [,39.8.8)[40.0.0-alpha.2,40.9.1)[41.0.0-alpha.1,41.2.1)[42.0.0-alpha.1,42.0.0-beta.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.11% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-18563341
  • published10 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

NewCVE-2026-70597  (opens in a new tab)
CWE-367  (opens in a new tab)

How to fix?

Upgrade org.webjars.npm:electron to version 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 or higher.

Overview

org.webjars.npm:electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition via the parent process code-sign verification on macOS. An attacker can execute arbitrary code within the context of a signed application by bypassing the code-sign check from a local process, potentially inheriting sensitive permissions and keychain access.

Note: This is only exploitable if fuse-based hardening restricting ELECTRON_RUN_AS_NODE and NODE_OPTIONS to same-signed parents is enabled.

CVSS Base Scores

version 4.0
version 3.1