electronjs records
40 published records for vendor electronjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 95%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-668 Exposure of Resource to Wrong Sphere7
- CWE-416 Use After Free5
- CWE-20 Improper Input Validation4
- CWE-501 Trust Boundary Violation3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-16151No exploit | Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects alelectronjs · electron · CWE-94 | Critical9.8 | — | 2.7% | Jun 6, 2018 |
39Monitor | CVE-2022-29247No exploit | Exposure of Resource to Wrong Sphere in Electronelectronjs · electron · CWE-668 | Critical9.8 | — | 1.0% | Jun 13, 2022 |
39Monitor | CVE-2020-4077No exploit | Context isolation bypass via contextBridge in Electronelectronjs · electron · CWE-501 | Critical9.9 | — | 1.0% | Jul 6, 2020 |
39Monitor | CVE-2023-23623No exploit | Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electronelectronjs · electron · CWE-670 | Critical9.8 | — | 0.7% | Sep 6, 2023 |
39Monitor | CVE-2026-34775No exploit | Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processeselectronjs · electron · CWE-653 | Critical9.8 | — | 0.4% | Apr 3, 2026 |
37Monitor | CVE-2020-35717Proof of concept | zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)electronjs · zonote · CWE-79 | Critical9.0 | — | 3.8% | Jan 1, 2021 |
36Monitor | CVE-2018-1000118No exploit | Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in electronjs · electron · CWE-78 | High8.8 | — | 2.4% | Mar 7, 2018 |
36Monitor | CVE-2021-32772No exploit | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entrieselectronjs · poddycast · CWE-78 | High8.8 | — | 2.4% | Aug 3, 2021 |
36Monitor | CVE-2020-4076No exploit | Context isolation bypass via leaked cross-context objects in Electronelectronjs · electron · CWE-501 | Critical9.0 | — | 0.4% | Jul 6, 2020 |
35Monitor | CVE-2018-15685Proof of concept | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandelectronjs · electron · CWE-1188 | High8.1 | — | 10.4% | Aug 23, 2018 |
35Monitor | CVE-2026-34769No exploit | Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceelectronjs · electron · CWE-88 | High8.8 | — | 0.4% | Apr 3, 2026 |
35Monitor | CVE-2026-34771No exploit | Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbackselectronjs · electron · CWE-416 | High8.8 | — | 0.4% | Apr 3, 2026 |
35Monitor | CVE-2026-34765No exploit | Electron named window.open targets not scoped to the opener's browsing contextelectronjs · electron · CWE-668 | High8.8 | — | 0.4% | Apr 7, 2026 |
35Monitor | CVE-2026-34770No exploit | Electron: Use-after-free in PowerMonitor on Windows and macOSelectronjs · electron · CWE-416 | High8.8 | — | 0.3% | Apr 3, 2026 |
35Monitor | CVE-2026-34772No exploit | Electron: Use-after-free in download save dialog callbackelectronjs · electron · CWE-416 | High8.8 | — | 0.2% | Apr 3, 2026 |
34Monitor | CVE-2018-1000136No exploit | Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webelectronjs · electron · CWE-20 | High8.1 | — | 5.1% | Mar 23, 2018 |
34Monitor | CVE-2021-39184No exploit | Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIelectronjs · electron · CWE-668 | High8.6 | — | 1.1% | Oct 12, 2021 |
34Monitor | CVE-2023-29198No exploit | Context isolation bypass via nested unserializable return value in Electronelectronjs · electron · CWE-754 | High8.5 | — | 0.6% | Sep 6, 2023 |
32Monitor | CVE-2026-34774No exploit | Electron: Use-after-free in offscreen child window paint callbackelectronjs · electron · CWE-416 | High8.1 | — | 0.6% | Apr 3, 2026 |
31Monitor | CVE-2026-34779No exploit | Electron: AppleScript injection in app.moveToApplicationsFolder on macOSelectronjs · electron · CWE-78 | High7.8 | — | 0.2% | Apr 3, 2026 |
31Monitor | CVE-2026-34768No exploit | Electron: Unquoted executable path in app.setLoginItemSettings on Windowselectronjs · electron · CWE-428 | High7.8 | — | 0.1% | Apr 3, 2026 |
30Monitor | CVE-2020-15174No exploit | Unpreventable top-level navigation in Electronelectronjs · electron · CWE-20 | High7.5 | — | 1.4% | Oct 6, 2020 |
30Monitor | CVE-2020-4075No exploit | Arbitrary file read via window-open IPC in Electronelectronjs · electron · CWE-552 | High7.5 | — | 1.2% | Jul 6, 2020 |
30Monitor | CVE-2026-34773No exploit | Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windowselectronjs · electron · CWE-20 | High7.5 | — | 0.3% | Apr 3, 2026 |
28Monitor | CVE-2022-29257No exploit | Electron's AutoUpdater module fails to validate certain nested components of the bundleelectronjs · electron · CWE-20 | High7.2 | — | 0.9% | Jun 13, 2022 |
- CVE-2017-1615140Plan
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects al
CriticalCVSS 9.8No exploitEPSS 3%electronjs · electronJun 6, 2018
- CVE-2022-2924739Monitor
Exposure of Resource to Wrong Sphere in Electron
CriticalCVSS 9.8No exploitEPSS 1%electronjs · electronJun 13, 2022
- CVE-2020-407739Monitor
Context isolation bypass via contextBridge in Electron
CriticalCVSS 9.9No exploitEPSS 1%electronjs · electronJul 6, 2020
- CVE-2023-2362339Monitor
Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron
CriticalCVSS 9.8No exploitEPSS 1%electronjs · electronSep 6, 2023
- CVE-2026-3477539Monitor
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
CriticalCVSS 9.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2020-3571737Monitor
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)
CriticalCVSS 9.0Proof of conceptEPSS 4%electronjs · zonoteJan 1, 2021
- CVE-2018-100011836Monitor
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in
HighCVSS 8.8No exploitEPSS 2%electronjs · electronMar 7, 2018
- CVE-2021-3277236Monitor
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entries
HighCVSS 8.8No exploitEPSS 2%electronjs · poddycastAug 3, 2021
- CVE-2020-407636Monitor
Context isolation bypass via leaked cross-context objects in Electron
CriticalCVSS 9.0No exploitEPSS 0%electronjs · electronJul 6, 2020
- CVE-2018-1568535Monitor
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sand
HighCVSS 8.1Proof of conceptEPSS 10%electronjs · electronAug 23, 2018
- CVE-2026-3476935Monitor
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
HighCVSS 8.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2026-3477135Monitor
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
HighCVSS 8.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2026-3476535Monitor
Electron named window.open targets not scoped to the opener's browsing context
HighCVSS 8.8No exploitEPSS 0%electronjs · electronApr 7, 2026
- CVE-2026-3477035Monitor
Electron: Use-after-free in PowerMonitor on Windows and macOS
HighCVSS 8.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2026-3477235Monitor
Electron: Use-after-free in download save dialog callback
HighCVSS 8.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2018-100013634Monitor
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Web
HighCVSS 8.1No exploitEPSS 5%electronjs · electronMar 23, 2018
- CVE-2021-3918434Monitor
Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
HighCVSS 8.6No exploitEPSS 1%electronjs · electronOct 12, 2021
- CVE-2023-2919834Monitor
Context isolation bypass via nested unserializable return value in Electron
HighCVSS 8.5No exploitEPSS 1%electronjs · electronSep 6, 2023
- CVE-2026-3477432Monitor
Electron: Use-after-free in offscreen child window paint callback
HighCVSS 8.1No exploitEPSS 1%electronjs · electronApr 3, 2026
- CVE-2026-3477931Monitor
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
HighCVSS 7.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2026-3476831Monitor
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
HighCVSS 7.8No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2020-1517430Monitor
Unpreventable top-level navigation in Electron
HighCVSS 7.5No exploitEPSS 1%electronjs · electronOct 6, 2020
- CVE-2020-407530Monitor
Arbitrary file read via window-open IPC in Electron
HighCVSS 7.5No exploitEPSS 1%electronjs · electronJul 6, 2020
- CVE-2026-3477330Monitor
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
HighCVSS 7.5No exploitEPSS 0%electronjs · electronApr 3, 2026
- CVE-2022-2925728Monitor
Electron's AutoUpdater module fails to validate certain nested components of the bundle
HighCVSS 7.2No exploitEPSS 1%electronjs · electronJun 13, 2022