CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-70609: electron before 39.8.7 (exclusive), from 40.0.0 (inclusive), before 40.9.0 (exclusive), from 41.0.0 (inclusive)…

CVE-2026-70609. CVSS 3.1 base score 5.7 (MEDIUM, Vendor/CNA). EPSS 0.0055 (percentile 0.44147), scored 2026-10-06.

Affected technology

electron · before 39.8.7 (exclusive)
electronjs

electron · from 40.0.0 (inclusive), before 40.9.0 (exclusive)
electronjs

electron · from 41.0.0 (inclusive), before 41.2.0 (exclusive)
electronjs

electron · 42.0.0 · update alpha1
electronjs

electron · 42.0.0 · update alpha2
electronjs

electron · 42.0.0 · update alpha3
electronjs

electron · 42.0.0 · update alpha4
electronjs

electron · 42.0.0 · update alpha5
electronjs

electron · 42.0.0 · update alpha6
electronjs

electron · 42.0.0 · update beta1
electronjs

electron · < 39.8.7, >= 40.0.0-alpha.1, < 40.9.0, >= 41.0.0-alpha.1, < 41.2.0, >= 42.0.0-alpha.1, < 42.0.0-beta.1
electron

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · High privileges required · User interaction required

What an attacker can do

If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js, including when untrusted input reaches the mode argument of openDevTools() or untrusted content calls openDevTools() on a webview it embeds. Vendor/CNA’s CVSS 3.1 assessment (base score 5.7/10) rates confidentiality and integrity impact as high; availability impact as none.

Published

CWE
CWE-94, CWE-116
CCR priority
22.9 /100 (P4)
CVSS 3.1
5.7 /10 · CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N · Vendor/CNA
EPSS
0.0055 · percentile 0.44252 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-70609.html