Origin Validation Error Affecting electron package, versions <39.8.9>=40.0.0-alpha.2 <40.9.2>=41.0.0-alpha.1 <41.2.2>=42.0.0-alpha.1 <42.0.0-beta.5


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.19% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ELECTRON-18563206
  • published6 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

NewCVE-2026-70601  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade electron to version 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5 or higher.

Overview

electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Origin Validation Error in contextBridge. An attacker can gain access to the isolated preload world and its capabilities by hijacking Function.prototype.bind when Promise-returning functions are exposed to untrusted web content. This may escalate to Node.js access if the renderer is unsandboxed or nodeIntegration is enabled.

Note: This is only exploitable if Promise-returning functions are exposed via contextBridge in windows that load untrusted content.

CVSS Base Scores

version 4.0
version 3.1