Origin Validation Error Affecting electron package, versions >=44.0.0-alpha.1 <44.0.0-beta.5>=43.0.0-alpha.1 <43.4.1>=42.0.0-alpha.1 <42.9.2<41.10.6


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ELECTRON-20335427
  • published30 Sept 2026
  • disclosed29 Sept 2026
  • creditmanus-use

Introduced: 29 Sep 2026

NewCVE-2026-102675  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade electron to version 44.0.0-beta.5, 43.4.1, 42.9.2, 41.10.6 or higher.

Overview

electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Origin Validation Error via the registerFileProtocol and registerHttpProtocol (URLPipeLoader) handlers in ElectronURLLoaderFactory, which fail to apply the opaque response tag to cross-origin mode=no-cors fetch requests. The file and http sinks build or forward their own response head, dropping the opaque tag computed in StartLoading, so the response is delivered as a basic, script-readable response instead of an opaque one. An attacker serving content through a registered custom protocol can read cross-origin responses that should be inaccessible to script.

Note: This is only exploitable if the application registers a custom file or HTTP protocol handler, serves it through one of those handlers, and loads untrusted content.

CVSS Base Scores

version 4.0
version 3.1