GHSA-v64r-4m7r-3mvq: Electron: HTTP redirect followed into local file loader
Impact
When following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed.
Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed (the default) and expose the response body. Apps that only request fixed, trusted URLs are not affected.
Workarounds
Set redirect: 'error' or redirect: 'manual' on requests to untrusted URLs and validate any redirect target before following it.
Fixed Versions
- 42.0.0-beta.3
- 41.2.1
- 40.9.0
- 39.8.8
For more information
If you have any questions or comments about this advisory, email Electron at security@electronjs.org
Details
Original advisory: https://github.com/advisories/GHSA-v64r-4m7r-3mvq
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70605 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from GitHub Security Advisories
- mediumGHSA-v93f-fgjr-hjrj: Electron: window.open features string controls some window options considered privileged2026-08-05
- mediumGHSA-r4w5-6pfg-jxp5: Electron: ProtocolResponse.url reuses the default session cache instead of the registerin…2026-08-05
- highGHSA-v3j7-r9gq-3gjw: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin re…2026-08-05
- mediumGHSA-m55f-7gqj-fr98: Electron: Extension tab APIs operate across session boundaries2026-08-05
- mediumGHSA-5c9j-mhmv-5xgx: Electron: shell.openPath path validation bypass via embedded null byte2026-08-05