Skip to content

fix(electron-app): update electron to address CVE - #508

Draft
valeriobelli wants to merge 1 commit into
callstackincubator:mainfrom
valeriobelli:upgrade-electron-addressing-security-issues
Draft

valeriobelli wants to merge 1 commit into
callstackincubator:mainfrom
valeriobelli:upgrade-electron-addressing-security-issues

Conversation

@valeriobelli

Copy link
Copy Markdown
Contributor

Description

Although used in development environments, the targeted electron version is affected by the following CVEs/GHSA (Generated by Claude and manually reviewed).

Generated 2026-09-19 from the GitHub Advisory Database and the electron/electron security advisories API.

CVE GHSA Severity Published Summary Affected → Patched
no CVE yet GHSA-vv43-5jgx-7qv8 medium 2026-08-29 Local race condition in Squirrel.Mac update installation on macOS < 39.8.1039.8.10
>= 40.0.0-alpha.1unpatched
>= 41.0.0-alpha.1, < 41.10.541.10.5
>= 42.0.0-alpha.1, < 42.0.0-beta.242.0.0-beta.2
no CVE yet GHSA-hq2x-r82h-9wj4 high 2026-08-29 Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab < 41.10.441.10.4
>= 42.0.0-alpha.1, < 42.5.242.5.2
>= 43.0.0-alpha.1, < 43.0.043.0.0
no CVE yet GHSA-gr2m-v5gq-v685 high 2026-08-29 Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions < 41.10.641.10.6
>= 42.0.0-alpha.1, < 42.9.242.9.2
>= 43.0.0-alpha.1, < 43.4.143.4.1
>= 44.0.0-alpha.1, < 44.0.0-beta.544.0.0-beta.5
no CVE yet GHSA-j84w-jfhq-vhvj high 2026-08-29 File and HTTP protocol handlers allow cross-origin reads without corsEnabled < 41.10.641.10.6
>= 42.0.0-alpha.1, < 42.9.242.9.2
>= 43.0.0-alpha.1, < 43.4.143.4.1
>= 44.0.0-alpha.1, < 44.0.0-beta.544.0.0-beta.5
no CVE yet GHSA-9qh4-3jw8-366w high 2026-08-29 <webview> can enable Node.js integration in Web Workers despite embedder restrictions < 41.10.641.10.6
>= 42.0.0-alpha.1, < 42.9.242.9.2
>= 43.0.0-alpha.1, < 43.4.143.4.1
>= 44.0.0-alpha.1, < 44.0.0-beta.544.0.0-beta.5
no CVE yet GHSA-qmv3-fv6v-rmhq high 2026-08-29 Sandboxed preload code cache can be poisoned by a compromised renderer >= 42.3.3, < 42.10.042.10.0
>= 43.0.0-beta.1, < 43.4.243.4.2
>= 44.0.0-alpha.1, < 44.0.0-beta.644.0.0-beta.6
CVE-2026-70612 GHSA-p2rr-rvmm-c5fp medium 2026-08-05 Sandboxed iframes can launch external protocol handlers < 39.8.839.8.8
>= 40.0.0-alpha.1, < 40.9.040.9.0
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70611 GHSA-f2r8-jv7c-xqmp medium 2026-08-05 DevTools embedder handler executes arbitrary files via shell open < 39.8.939.8.9
>= 40.0.0-alpha.1, < 40.9.240.9.2
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70610 GHSA-ff2p-hmqr-hxm4 medium 2026-08-05 contextBridge object copy honors prototype setters < 39.8.939.8.9
>= 40.0.0-alpha.1, < 40.9.240.9.2
>= 41.0.0-alpha.1, < 41.2.241.2.2
>= 42.0.0-alpha.1, < 42.0.0-beta.442.0.0-beta.4
CVE-2026-70609 GHSA-4f78-qhmw-8j8m medium 2026-08-05 DevTools JavaScript Injection via Unsanitized Dock State Parameter < 39.8.739.8.7
>= 40.0.0-alpha.1, < 40.9.040.9.0
>= 41.0.0-alpha.1, < 41.2.041.2.0
>= 42.0.0-alpha.1, < 42.0.0-beta.142.0.0-beta.1
CVE-2026-70608 GHSA-9f4c-93c8-jc8g high 2026-08-05 Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path >= 42.0.0-alpha.1, < 42.0.142.0.1
>= 40.0.0-alpha.1, < 41.10.341.10.3
< 39.8.1039.8.10
CVE-2026-70607 GHSA-v93f-fgjr-hjrj medium 2026-08-05 window.open features string controls some window options considered privileged < 39.8.839.8.8
>= 40.0.0-alpha.1, < 40.9.040.9.0
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70606 GHSA-r4w5-6pfg-jxp5 medium 2026-08-05 ProtocolResponse.url reuses the default session cache instead of the registering session >= 43.0.0-alpha.1, < 43.0.043.0.0
>= 42.0.0-alpha.1, < 42.5.142.5.1
>= 41.0.0-alpha.1, < 41.9.141.9.1
>= 40.0.0-alpha.1, < 40.10.640.10.6
CVE-2026-70605 GHSA-v64r-4m7r-3mvq medium 2026-08-05 HTTP redirect followed into local file loader < 39.8.839.8.8
>= 40.0.0-alpha.1, < 40.9.040.9.1
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70604 GHSA-v3j7-r9gq-3gjw high 2026-08-05 Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads >= 42.0.0-alpha.1, < 42.0.042.0.0
>= 41.0.0-alpha.1, < 41.4.041.4.0
>= 40.0.0-alpha.1, < 40.9.340.9.3
< 39.8.1039.8.10
CVE-2026-70602 GHSA-m55f-7gqj-fr98 medium 2026-08-05 Extension tab APIs operate across session boundaries < 39.8.839.8.8
>= 40.0.0-alpha.1, < 40.9.040.9.0
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70603 GHSA-5c9j-mhmv-5xgx medium 2026-08-05 shell.openPath path validation bypass via embedded null byte >= 42.0.0-alpha.1, < 42.0.0-beta.142.0.0-beta.1
>= 41.0.0-alpha.1, < 41.1.141.1.1
>= 40.0.0-alpha.1, < 40.9.040.9.0
< 39.8.639.8.6
CVE-2026-70601 GHSA-h7rp-cf8h-j98x high 2026-08-05 Context isolation bypass via Function.prototype.bind hijack < 39.8.939.8.9
>= 40.0.0-alpha.1, < 40.9.240.9.2
>= 41.0.0-alpha.1, < 41.2.241.2.2
>= 42.0.0-alpha.1, < 42.0.0-beta.542.0.0-beta.5
CVE-2026-70600 GHSA-x8rc-wpg4-grpf low 2026-08-05 Cross-origin iframe can position native autofill popup < 39.8.839.8.8
>= 40.0.0-alpha.1, < 40.9.040.9.1
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70599 GHSA-9pf5-hg6p-4pwp medium 2026-08-05 Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin < 39.8.739.8.7
>= 40.0.0-alpha.1, < 40.9.040.9.0
>= 41.0.0-alpha.1, < 41.2.041.2.0
>= 42.0.0-alpha.1, < 42.0.0-beta.142.0.0-beta.1
CVE-2026-70598 GHSA-pfmc-3mgc-p6fp low 2026-08-05 Off-screen rendering trusts GPU-supplied geometry over shared-memory size < 39.8.1039.8.10
>= 40.0.0-alpha.1, < 40.9.040.9.0
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-70597 GHSA-jm7p-cc5g-qwxx medium 2026-08-05 Parent process code-sign check is spoofable < 39.8.839.8.8
>= 40.0.0-alpha.1, < 40.9.040.9.1
>= 41.0.0-alpha.1, < 41.2.141.2.1
>= 42.0.0-alpha.1, < 42.0.0-beta.342.0.0-beta.3
CVE-2026-54257 GHSA-q6m5-f73j-m9mc critical 2026-06-15 Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow >= 42.3.1, < 42.3.342.3.3
CVE-2026-34781 GHSA-f37v-82c4-4x64 low 2026-04-07 Crash in clipboard.readImage() on malformed clipboard image data < 39.8.539.8.5
>= 40.0.0-alpha.1, < 40.8.540.8.5
>= 41.0.0-alpha.1, < 41.1.041.1.0
>= 42.0.0-alpha.1, < 42.0.0-alpha.542.0.0-alpha.5
CVE-2026-34765 GHSA-f3pv-wv63-48x8 medium 2026-04-07 Named window.open targets not scoped to the opener's browsing context < 39.8.539.8.5
>= 40.0.0-alpha.1, < 40.8.540.8.5
>= 41.0.0-alpha.1, < 41.1.041.1.0
>= 42.0.0-alpha.1, < 42.0.0-alpha.542.0.0-alpha.5
CVE-2026-34764 GHSA-8x5q-pvf5-64mp low 2026-04-03 Use-after-free in offscreen shared texture release() callback >= 33.0.0-alpha.1, < 39.8.539.8.5
>= 40.0.0-alpha.1, < 40.8.540.8.5
>= 41.0.0-alpha.1, < 41.1.041.1.0
>= 42.0.0-alpha.1, < 42.0.0-alpha.542.0.0-alpha.5
CVE-2026-34780 GHSA-jfqg-hf23-qpw2 high 2026-04-03 Context Isolation bypass via contextBridge VideoFrame transfer >= 39.0.0-alpha.1, < 39.8.039.8.0
>= 40.0.0-alpha.1, < 40.7.040.7.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2026-34779 GHSA-5rqw-r77c-jp79 medium 2026-04-03 AppleScript injection in app.moveToApplicationsFolder on macOS < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.040.8.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2026-34778 GHSA-xj5x-m3f3-5x3h medium 2026-04-03 Service worker can spoof executeJavaScript IPC replies < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.140.8.1
>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34777 GHSA-r5p7-gp4j-qhrx medium 2026-04-03 Incorrect origin passed to permission request handler for iframe requests < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.140.8.1
>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34776 GHSA-3c8v-cfp5-9885 medium 2026-04-03 Out-of-bounds read in second-instance IPC on macOS and Linux < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.140.8.1
>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34775 GHSA-xwr5-m59h-vwqr medium 2026-04-03 nodeIntegrationInWorker not correctly scoped in shared renderer processes < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.439.8.4
>= 40.0.0-alpha.1, < 40.8.440.8.4
>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34774 GHSA-532v-xpq5-8h95 high 2026-04-03 Use-after-free in offscreen child window paint callback < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.7.040.7.0
>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34773 GHSA-mwmh-mq4g-g6gr medium 2026-04-03 Registry key path injection in app.setAsDefaultProtocolClient on Windows < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.140.8.1
>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34772 GHSA-9w97-2464-8783 medium 2026-04-03 Use-after-free in download save dialog callback < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.039.8.0
>= 40.0.0-alpha.1, < 40.7.040.7.0
>= 41.0.0-alpha.1, < 41.0.0-beta.741.0.0-beta.7
CVE-2026-34771 GHSA-8337-3p73-46f4 high 2026-04-03 Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.039.8.0
>= 40.0.0-alpha.1, < 40.7.040.7.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2026-34770 GHSA-jjp3-mq3x-295m high 2026-04-03 Use-after-free in PowerMonitor on Windows and macOS < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.040.8.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2026-34769 GHSA-9wfr-w7mm-pc7f high 2026-04-03 Renderer command-line switch injection via undocumented commandLineSwitches webPreference < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.039.8.0
>= 40.0.0-alpha.1, < 40.7.040.7.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2026-34768 GHSA-jfqx-fxh3-c62j low 2026-04-03 Unquoted executable path in app.setLoginItemSettings on Windows < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.139.8.1
>= 40.0.0-alpha.1, < 40.8.040.8.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2026-34767 GHSA-4p4r-m79c-wq3v medium 2026-04-03 HTTP Response Header Injection in custom protocol handlers and webRequest < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.339.8.3
>= 40.0.0-alpha.1, < 40.8.340.8.3
>= 41.0.0-alpha.1, < 41.0.341.0.3
CVE-2026-34766 GHSA-9899-m83m-qhpj low 2026-04-03 USB device selection not validated against filtered device list < 38.8.638.8.6
>= 39.0.0-alpha.1, < 39.8.039.8.0
>= 40.0.0-alpha.1, < 40.7.040.7.0
>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
CVE-2025-55305 GHSA-vmqv-hx8q-j7mg medium 2025-09-03 Electron has ASAR Integrity Bypass via resource modification < 35.7.535.7.5
>= 36.0.0-alpha.1, < 36.8.136.8.1
>= 37.0.0-alpha.1, < 37.3.137.3.1
>= 38.0.0-alpha.1, < 38.0.0-beta.638.0.0-beta.6

Related Issue

No related issue in the issues list.

Testing

Automated:

  • pnpm --filter @rozenite/sqlite-plugin build
  • pnpm --filter @rozenite/sqlite-plugin test — 49 tests passed
  • pnpm --filter @rozenite/sqlite-plugin typecheck
  • pnpm --filter @rozenite/sqlite-plugin lint

Manual verification (confirmed in the requested environment):

  • Started electron-app manually using the available bin
  • Started electron-app through the rozenite available binary

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant