Skip to content
Noroxi

electronjs records

40 published records for vendor electronjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
95%
Median publish → KEV
No record has entered KEV

All records

40 records
  • Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects al

    CriticalCVSS 9.8No exploitEPSS 3%

    electronjs · electronJun 6, 2018

  • Exposure of Resource to Wrong Sphere in Electron

    CriticalCVSS 9.8No exploitEPSS 1%

    electronjs · electronJun 13, 2022

  • CVE-2020-4077
    39Monitor

    Context isolation bypass via contextBridge in Electron

    CriticalCVSS 9.9No exploitEPSS 1%

    electronjs · electronJul 6, 2020

  • Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron

    CriticalCVSS 9.8No exploitEPSS 1%

    electronjs · electronSep 6, 2023

  • Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

    CriticalCVSS 9.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)

    CriticalCVSS 9.0Proof of conceptEPSS 4%

    electronjs · zonoteJan 1, 2021

  • Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in

    HighCVSS 8.8No exploitEPSS 2%

    electronjs · electronMar 7, 2018

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entries

    HighCVSS 8.8No exploitEPSS 2%

    electronjs · poddycastAug 3, 2021

  • CVE-2020-4076
    36Monitor

    Context isolation bypass via leaked cross-context objects in Electron

    CriticalCVSS 9.0No exploitEPSS 0%

    electronjs · electronJul 6, 2020

  • GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sand

    HighCVSS 8.1Proof of conceptEPSS 10%

    electronjs · electronAug 23, 2018

  • Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

    HighCVSS 8.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

    HighCVSS 8.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Electron named window.open targets not scoped to the opener's browsing context

    HighCVSS 8.8No exploitEPSS 0%

    electronjs · electronApr 7, 2026

  • Electron: Use-after-free in PowerMonitor on Windows and macOS

    HighCVSS 8.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Electron: Use-after-free in download save dialog callback

    HighCVSS 8.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Web

    HighCVSS 8.1No exploitEPSS 5%

    electronjs · electronMar 23, 2018

  • Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API

    HighCVSS 8.6No exploitEPSS 1%

    electronjs · electronOct 12, 2021

  • Context isolation bypass via nested unserializable return value in Electron

    HighCVSS 8.5No exploitEPSS 1%

    electronjs · electronSep 6, 2023

  • Electron: Use-after-free in offscreen child window paint callback

    HighCVSS 8.1No exploitEPSS 1%

    electronjs · electronApr 3, 2026

  • Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

    HighCVSS 7.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Electron: Unquoted executable path in app.setLoginItemSettings on Windows

    HighCVSS 7.8No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Unpreventable top-level navigation in Electron

    HighCVSS 7.5No exploitEPSS 1%

    electronjs · electronOct 6, 2020

  • CVE-2020-4075
    30Monitor

    Arbitrary file read via window-open IPC in Electron

    HighCVSS 7.5No exploitEPSS 1%

    electronjs · electronJul 6, 2020

  • Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

    HighCVSS 7.5No exploitEPSS 0%

    electronjs · electronApr 3, 2026

  • Electron's AutoUpdater module fails to validate certain nested components of the bundle

    HighCVSS 7.2No exploitEPSS 1%

    electronjs · electronJun 13, 2022