| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hq2x-r82h-9wj4 | Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-281 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 30 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Electron
Electron electron |
|
| Vendors & Products |
Electron
Electron electron |
Tue, 29 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0. | |
| Title | Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab | |
| Weaknesses | CWE-346 CWE-693 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-30T20:11:08.290Z
Reserved: 2026-09-29T16:10:04.075Z
Link: CVE-2026-102673
Updated: 2026-09-30T19:33:53.702Z
Status : Awaiting Analysis
Published: 2026-09-29T17:17:07.487
Modified: 2026-09-30T21:17:04.917
Link: CVE-2026-102673
OpenCVE Enrichment
Updated: 2026-10-02T02:00:14Z
Github GHSA