Electron is a framework for building cross-platform desktop applications using web technologies, and vulnerabilities affecting it propagate across a broad ecosystem of dependent applications built on the platform despite a narrow direct product list. Flaws in Electron itself and applications built atop it skew toward serious outcomes, with a meaningful share reaching critical severity, driven by the framework's privileged access to system resources and the complexity of sandboxing enforcement in chromium-based runtimes. The recurring vulnerability classes center on resource-exposure issues, use-after-free conditions, input-validation gaps, and OS command injection, reflecting both the memory-safety demands of native code layers and the boundary between web-accessible surfaces and host-system capabilities. Defenders should treat Electron framework advisories as broadly relevant and monitor applications built on the platform for upstream patches, since remediation often requires coordinated updates across the application layer. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Electronjs over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15685HIGH GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a Web | Aug 23, 2018 | 8.1 | 42 | NO | YES |
CVE-2026-34775CRITICAL Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInW | Apr 4, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-34765HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls w | Apr 7, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-34772HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow | Apr 4, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-34771HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that regis | Apr 4, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-34769HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented | Apr 4, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-34774HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen render | Apr 4, 2026 | 8.1 | 31 | NO | NO |
CVE-2025-5805HIGH Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a thr | Jan 22, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34779HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.m | Apr 4, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-34768HIGH Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app | Apr 4, 2026 | 7.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Electronjs.
Media articles that mention a CVE ID that affects a product developed by Electronjs — matched by CVE ID, not by vendor name.