CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-v93f-fgjr-hjrj: Electron: window.open features string controls some window options considered privileged

mediumCVSS 5.3CVE-2026-70607
Impact Some window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths. Apps are only affected if untrusted content can call window.open() and the app does not override child window options via setWindowOpenHandler. Apps that deny window.open() for untrusted content, or set overrideBrowserWindowOptions explicitly, are not affected. Workarounds Return { action: 'deny' } from setWindowOpenHandler for untrusted content, or supply overrideBrowserWindowOptions so every window option is set explicitly. Fixed Versions - 42.0.0-beta.3 - 41.2.1 - 40.9.0 - 39.8.8 For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 5.3
Published
2026-08-05
Last updated
2026-08-05
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-v93f-fgjr-hjrj

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-70607coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories