Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34780

26
FAUCET Score

CVE-2026-34780 describes a high-severity context isolation bypass vulnerability in Electron, affecting versions 39.x, 40.x, and 41.x, specifically when applications bridge VideoFrame objects across the contextBridge. Rated 8.3 HIGH, an attacker who can execute JavaScript in the main world (e.g., via XSS) can leverage this to gain access to the isolated world and Node.js APIs, leading to full application compromise. Exploitation requires high attack complexity and user interaction, relying on specific application configurations and a prior compromise. While there is no public exploit code or evidence of active exploitation, the CVE is on the Hot List and has garnered some community discussion. Organizations should update to patched versions 39.8.0, 40.7.0, or 41.0.0-beta.8 if affected.

Impacted Technologies

VendorProductVersion(s)CPE
>= 39.0.0, < 39.8.0CPE matchmatch criteria
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
>= 40.0.0, < 40.7.0CPE matchmatch criteria
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
41.0.0CPE matchmatch criteria
cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:*
41.0.0CPE matchmatch criteria
cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:*
41.0.0CPE matchmatch criteria
cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.3HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 25th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

npmpatch availablevia ghsa
Product: electronFixed in: 39.8.0
npmpatch availablevia ghsa
Product: electronFixed in: 40.7.0
npmpatch availablevia ghsa
Product: electronFixed in: 41.0.0-beta.8
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-jfqg-hf23-qpw2high

Electron: Context Isolation bypass via contextBridge VideoFrame transfer

Apr 3, 2026

References

access.redhat.com / security/cve/CVE-2026-34780
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-34780.json
github.com / electron/electron/security/advisories/GHSA-jfqg-hf23-qpw2
Vendor Advisory