You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name. If that existing child was created with more permissive webPreferences (via setWindowOpenHandler's overrideBrowserWindowOptions), content loaded by the second renderer inherits those permissions. Apps are only affected if they open multiple top-level windows with differing trust levels and use setWindowOpenHandler to grant child windows elevated webPreferences such as a privileged preload script. Apps that do not elevate child window privileges, or that use a single top-level window, are not affected. Apps that additionally grant nodeIntegration: true or sandbox: false to child windows (contrary to the security recommendations) may be exposed to arbitrary code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Electron, Description: Electron es un framework para escribir aplicaciones de escritorio multiplataforma usando JavaScript, HTML y CSS. Antes de 39.8.5, 40.8.5, 41.1.0 y 42.0.0-alpha.5, cuando un renderizador llama a window.open() con un nombre de destino, Electron no delimitaba correctamente la búsqueda de la ventana con nombre al grupo de contexto de navegación del abridor. Un renderizador podía navegar una ventana secundaria existente que fue abierta por un renderizador diferente y no relacionado si ambos usaban el mismo nombre de destino. Si esa ventana secundaria existente fue creada con webPreferences más permisivas (a través de overrideBrowserWindowOptions de setWindowOpenHandler), el contenido cargado por el segundo renderizador hereda esos permisos. Las aplicaciones solo se ven afectadas si abren múltiples ventanas de nivel superior con diferentes niveles de confianza y usan setWindowOpenHandler para otorgar a las ventanas secundarias webPreferences elevadas, como un script de precarga privilegiado. Las aplicaciones que no elevan los privilegios de las ventanas secundarias, o que usan una única ventana de nivel superior, no se ven afectadas. Las aplicaciones que además otorgan nodeIntegration: true o sandbox: false a las ventanas secundarias (contrario a las recomendaciones de seguridad) pueden estar expuestas a ejecución de código arbitrario. Esta vulnerabilidad está corregida en 39.8.5, 40.8.5, 41.1.0 y 42.0.0-alpha.5.
OR
*cpe:2.3:a:electronjs:electron:41.2.0:*:*:*:*:node.js:*:*
*cpe:2.3:a:electronjs:electron:42.0.0:alpha1:*:*:*:node.js:*:*
*cpe:2.3:a:electronjs:electron:42.0.0:alpha2:*:*:*:node.js:*:*
*cpe:2.3:a:electronjs:electron:42.0.0:alpha3:*:*:*:node.js:*:*
*cpe:2.3:a:electronjs:electron:42.0.0:alpha4:*:*:*:node.js:*:*
*cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* versions up to (including) 39.8.4
*cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* versions from (including) 40.0.0 up to (including) 40.8.4
*cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* versions from (including) 41.0.0 up to (excluding) 41.1.0
New CVE Received from GitHub, Inc.4/07/2026 6:16:22 PM
Action
Type
Old Value
New Value
Added
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name. If that existing child was created with more permissive webPreferences (via setWindowOpenHandler's overrideBrowserWindowOptions), content loaded by the second renderer inherits those permissions. Apps are only affected if they open multiple top-level windows with differing trust levels and use setWindowOpenHandler to grant child windows elevated webPreferences such as a privileged preload script. Apps that do not elevate child window privileges, or that use a single top-level window, are not affected. Apps that additionally grant nodeIntegration: true or sandbox: false to child windows (contrary to the security recommendations) may be exposed to arbitrary code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.