CVE-2026-34775 is a medium-severity vulnerability in the Electron framework, impacting applications that enable the nodeIntegrationInWorker webPreference in versions prior to 38.8.6, 39.8.4, 40.8.4, and 41.0.0. The flaw allows workers in specific process-sharing scenarios to incorrectly gain Node.js integration, even when explicitly disabled, which could lead to high confidentiality and integrity impacts. Rated with a CVSS score of 6.8, successful exploitation requires network access, high attack complexity, and user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 38.8.6CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 39.0.0, < 39.8.4CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 40.0.0, < 40.8.4CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.