Improper Neutralization of Null Byte or NUL Character Affecting electron package, versions <39.8.6>=40.0.0-alpha.2 <40.9.1>=41.0.0-alpha.1 <41.1.1>=42.0.0-alpha.1 <42.0.0-beta.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ELECTRON-18563328
  • published6 Aug 2026
  • disclosed5 Aug 2026
  • creditYassine Bengana, Maxence Schmitt

Introduced: 5 Aug 2026

NewCVE-2026-70603  (opens in a new tab)
CWE-158  (opens in a new tab)

How to fix?

Upgrade electron to version 39.8.6, 40.9.1, 41.1.1, 42.0.0-beta.1 or higher.

Overview

electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Improper Neutralization of Null Byte or NUL Character via the shell.openPath function. An attacker can bypass file path validation by supplying a path containing an embedded null byte, which may result in opening a different file than intended.

Note: This is only exploitable if paths derived from untrusted input are passed to shell.openPath and only string-based validation is performed without a filesystem check.

Workaround

This vulnerability can be mitigated by rejecting any path containing a null byte before passing it to shell.openPath.

References

CVSS Base Scores

version 4.0
version 3.1