GHSA-9qh4-3jw8-366w: High severity npm/electron vulnerability

Published Sep 29, 2026
·
Updated

Impact

A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.

Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.

Workarounds

Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.

Fixed Versions

44.0.0-beta.5 43.4.1 42.9.2 41.10.6

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Affected Software

4 affected componentsFixes available
npm/electron>=44.0.0-alpha.1<44.0.0-beta.5
44.0.0-beta.5
npm/electron>=43.0.0-alpha.1<43.4.1
43.4.1
npm/electron>=42.0.0-alpha.1<42.9.2
42.9.2
npm/electron<41.10.6
41.10.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 44.0.0-beta.5
  2. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 43.4.1
  3. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 42.9.2
  4. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 41.10.6
  5. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 41.10.6
  6. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 42.9.2
  7. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 43.4.1
  8. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 44.0.0-beta.5
  9. Configuration

    Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.

    Electron <webview> nodeIntegrationInWorker = removed

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:02 PM
Data Sourced
via GitHub·06:02 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which Electron applications are affected?

An application is affected only if it enables the <webview> tag and uses an unsandboxed embedder. Applications that do not use <webview>, or that keep the embedder sandboxed, are not affected.

2

What must an attacker be able to do to exploit this issue?

The attacker must be able to get guest content loaded in a <webview> where Node.js integration in workers can be enabled through guest preferences. Exploitation also requires user interaction, as indicated by the UI:R vector.

3

What can be done if upgrading is not immediately possible?

In a will-attach-webview handler, remove nodeIntegrationInWorker from the guest preferences. Alternatively, do not enable the <webview> tag when loading untrusted content.

4

How can I determine whether my application needs remediation?

Review whether the application enables <webview>, whether its embedder is unsandboxed, and whether guest preferences can include nodeIntegrationInWorker. If <webview> is not used or the embedder remains sandboxed, the advisory states the application is not affected.

5

Which releases contain fixes?

Fixed releases are 44.0.0-beta.5, 43.4.1, 42.9.2, and 41.10.6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203