Origin Validation Error Affecting electron package, versions >=43.0.0-alpha.1 <43.0.0>=42.0.0-alpha.1 <42.5.2<41.10.4<45.0.0-alpha.10


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.15% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ELECTRON-20335498
  • published30 Sept 2026
  • disclosed29 Sept 2026
  • creditUnknown

Introduced: 29 Sep 2026

NewCVE-2026-102673  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade electron to version 43.0.0, 42.5.2, 41.10.4, 45.0.0-alpha.10 or higher.

Overview

electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.

Affected versions of this package are vulnerable to Origin Validation Error via the OpenURLFromTab navigation path, when a sandboxed iframe with allow-popups but without allow-popups-to-escape-sandbox opens a new window. The initiating frame's sandbox restrictions are not resolved on this code path because params.frame_tree_node_id is unset for non-CURRENT_TAB dispositions, causing the sandbox check to never run. As a result, the newly created window receives full origin authority instead of inheriting the opener frame's sandbox flags, allowing a sandboxed frame to escape its confinement.

Note: This is only exploitable if the app embeds untrusted content in iframes sandboxed with allow-scripts allow-popups.

CVSS Base Scores

version 4.0
version 3.1