Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qmv3-fv6v-rmhq | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer |
Tue, 29 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6. | |
| Title | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer | |
| Weaknesses | CWE-20 CWE-345 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T17:43:26.960Z
Reserved: 2026-09-29T16:10:04.075Z
Link: CVE-2026-102677
No data.
Status : Received
Published: 2026-09-29T18:17:09.573
Modified: 2026-09-29T18:17:09.573
Link: CVE-2026-102677
No data.
OpenCVE Enrichment
No data.
Github GHSA