CVE-2026-70612: Medium severity npm/electron vulnerability
Impact Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app's permission handlers.
Apps are only affected if they render untrusted content in sandboxed iframes and grant the openExternal permission (granted by default when no setPermissionRequestHandler is installed). Apps whose permission handler denies openExternal for untrusted content are not affected.
Workarounds Install a setPermissionRequestHandler that denies the openExternal permission for untrusted content.
Fixed Versions 42.0.0-beta.3 41.2.1 40.9.0 39.8.8
For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.0.0-beta.3 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.2.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 40.9.0 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 39.8.8 - Upgrade
Upgrade
electron/electronto a version that resolves this vulnerability.Fixed in 39.8.8 - Upgrade
Upgrade
electron/electronto a version that resolves this vulnerability.Fixed in 40.9.0 - Upgrade
Upgrade
electron/electronto a version that resolves this vulnerability.Fixed in 41.2.1 - Upgrade
Upgrade
electron/electronto a version that resolves this vulnerability.Fixed in 42.0.0-beta.3 - Configuration
Install a setPermissionRequestHandler that denies the openExternal permission for untrusted content in sandboxed iframes.
Electron (setPermissionRequestHandler for webContents permission requests) openExternal permission handling for untrusted content in sandboxed iframes = deny