CVE-2026-34769 is a high-severity vulnerability in the Electron framework, affecting versions prior to 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, specifically impacting applications that process untrusted input for webPreferences. This flaw allows an attacker to inject arbitrary command-line switches, potentially disabling renderer sandboxing or web security controls. Rated with a CVSS score of 7.7 (High), exploitation requires local access, high attack complexity, and user interaction, with potential for high impact on confidentiality, integrity, and availability. While this CVE is on an "Active" hot list, there is currently no public exploit code available, nor is it listed in CISA's Known Exploited Vulnerabilities catalog, though it has garnered limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 38.8.6CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 39.0.0, < 39.8.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 40.0.0, < 40.7.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.