Exposure of Data Element to Wrong Session Affecting electron package, versions <39.8.8>=40.0.0-alpha.2 <40.9.1>=41.0.0-alpha.1 <41.2.1>=42.0.0-alpha.1 <42.0.0-beta.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ELECTRON-18563356
  • published6 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

NewCVE-2026-70602  (opens in a new tab)
CWE-488  (opens in a new tab)

How to fix?

Upgrade electron to version 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 or higher.

Overview

electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Exposure of Data Element to Wrong Session via the extension tab and scripting APIs not being properly scoped to the extension's own session. An attacker can access, navigate, and read data from windows belonging to a different session by loading a malicious or compromised extension.

Note: This is only exploitable if Chrome extensions are loaded via session.loadExtension and the application relies on separate sessions to isolate extensions from other content.

Workaround

This vulnerability can be mitigated by only loading extensions from trusted sources and not relying solely on session separation for isolation.

References

CVSS Base Scores

version 4.0
version 3.1