GHSA-hq2x-r82h-9wj4: High severity npm/electron vulnerability

Published Sep 29, 2026
·
Updated

Impact

Popups opened from a sandboxed iframe through a link (for example target="blank" or a middle-click) did not inherit the iframe's HTML sandbox restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.

Apps are only affected if they embed untrusted content in iframes sandboxed with allow-scripts allow-popups. Apps that do not embed untrusted content in sandboxed iframes are not affected.

Workarounds

Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.

Fixed Versions

43.0.0 42.5.2 41.10.4

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Affected Software

3 affected componentsFixes available
npm/electron>=43.0.0-alpha.1<43.0.0
43.0.0
npm/electron>=42.0.0-alpha.1<42.5.2
42.5.2
npm/electron<41.10.4
41.10.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 43.0.0
  2. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 42.5.2
  3. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 41.10.4
  4. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 41.10.4
  5. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 42.5.2
  6. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 43.0.0
  7. Configuration

    Do not apply allow-popups to sandboxed iframes that render untrusted content.

    Electron sandboxed iframes allow-popups = disabled
  8. Configuration

    Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames.

    Electron WebContents setWindowOpenHandler = deny or constrain popups

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:05 PM
Data Sourced
via GitHub·06:05 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which Electron applications are exposed to this issue?

Applications are affected only if they embed untrusted content in sandboxed iframes configured with both allow-scripts and allow-popups. Applications that do not embed untrusted content in sandboxed iframes are not affected.

2

What must an attacker do to exploit the vulnerability?

An attacker needs untrusted content to execute inside an affected sandboxed iframe and open a popup, such as through a target="_blank" link or a middle-click. The resulting popup can receive the embedding application's full origin rather than the iframe's sandbox restrictions.

3

What could a successful exploit allow?

The popup may gain access to the embedding application's cookies, storage, and same-origin scripting capabilities. This can expose data associated with the embedding application's origin and permit limited integrity impact.

4

What can be done if updating Electron is not immediately possible?

Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames. Alternatively, do not grant allow-popups to sandboxed iframes that render untrusted content.

5

Which Electron releases contain the fix?

The issue is fixed in Electron 43.0.0, 42.5.2, and 41.10.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203