CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-f2r8-jv7c-xqmp: Electron: DevTools embedder handler executes arbitrary files via shell open

mediumCVSS 6.9CVE-2026-70611
Impact The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native code outside the sandbox. Apps are only affected if DevTools is opened for windows exposed to untrusted content or untrusted DevTools extensions. Apps that do not open DevTools in that context are not affected. Workarounds Do not open DevTools for windows that load untrusted content, and do not load untrusted DevTools extensions. Fixed Versions - 42.0.0-beta.3 - 41.2.1 - 40.9.2 - 39.8.9 For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 6.9
Published
2026-08-05
Last updated
2026-08-05
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-f2r8-jv7c-xqmp

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-70611coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories