Time-of-check Time-of-use (TOCTOU) Race Condition Affecting electron package, versions <39.8.8>=40.0.0-alpha.2 <40.9.1>=41.0.0-alpha.1 <41.2.1>=42.0.0-alpha.1 <42.0.0-beta.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.08% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ELECTRON-18563340
  • published6 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

NewCVE-2026-70597  (opens in a new tab)
CWE-367  (opens in a new tab)

How to fix?

Upgrade electron to version 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 or higher.

Overview

electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition via the parent process code-sign verification on macOS. An attacker can execute arbitrary code within the context of a signed application by bypassing the code-sign check from a local process, potentially inheriting sensitive permissions and keychain access.

Note: This is only exploitable if fuse-based hardening restricting ELECTRON_RUN_AS_NODE and NODE_OPTIONS to same-signed parents is enabled.

CVSS Base Scores

version 4.0
version 3.1