GHSA-j84w-jfhq-vhvj: High severity npm/electron vulnerability
Impact
Responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI: true but without corsEnabled: true could be read cross-origin by web content. This completes the fix for CVE-2026-70604.
Apps are only affected if they register such a scheme, serve it through one of those handlers, and load untrusted content. Apps that set corsEnabled: true, or that do not load untrusted content, are not affected.
Workarounds
Set corsEnabled: true on the scheme, or do not load untrusted content in windows that can reach it.
Fixed Versions
44.0.0-beta.5 43.4.1 42.9.2 41.10.6
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 44.0.0-beta.5 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 43.4.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.9.2 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.10.6 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 41.10.6 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 42.9.2 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 43.4.1 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 44.0.0-beta.5 - Configuration
Set corsEnabled: true on the custom scheme to prevent cross-origin reads of responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol.
Electron custom scheme corsEnabled = true
Event History
Frequently Asked Questions
Which applications are affected?
An application is affected only if it registers a custom scheme with supportFetchAPI: true, serves that scheme using protocol.registerFileProtocol or protocol.registerHttpProtocol, and loads untrusted content. Applications that do not load untrusted content are not affected.
What does an attacker need to exploit this issue?
An attacker needs untrusted web content to be loaded in a window that can reach the affected custom scheme. That content can then read responses from the scheme cross-origin.
Does enabling CORS avoid the issue?
Yes. Applications that set corsEnabled: true on the custom scheme are not affected.
What can be done before updating Electron?
Set corsEnabled: true for the affected scheme, or prevent untrusted content from being loaded in windows that can access it. Fixed releases are 44.0.0-beta.5, 43.4.1, 42.9.2, and 41.10.6.
How can I determine whether my application is exposed?
Review custom scheme registration and protocol handlers. Exposure requires supportFetchAPI: true without corsEnabled: true, use of registerFileProtocol or registerHttpProtocol for that scheme, and a path for untrusted content to load in a window that can access it.