GHSA-v93f-fgjr-hjrj: Electron: window.open features string controls some window options considered privileged
Impact
Some window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths.
Apps are only affected if untrusted content can call window.open() and the app does not override child window options via setWindowOpenHandler. Apps that deny window.open() for untrusted content, or set overrideBrowserWindowOptions explicitly, are not affected.
Workarounds
Return { action: 'deny' } from setWindowOpenHandler for untrusted content, or supply overrideBrowserWindowOptions so every window option is set explicitly.
Fixed Versions
- 42.0.0-beta.3
- 41.2.1
- 40.9.0
- 39.8.8
For more information
If you have any questions or comments about this advisory, email Electron at security@electronjs.org
Details
Original advisory: https://github.com/advisories/GHSA-v93f-fgjr-hjrj
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70607 | coverage & exploitation status | NVD · CVE.org |
More from GitHub Security Advisories
- mediumGHSA-r4w5-6pfg-jxp5: Electron: ProtocolResponse.url reuses the default session cache instead of the registerin…2026-08-05
- mediumGHSA-v64r-4m7r-3mvq: Electron: HTTP redirect followed into local file loader2026-08-05
- highGHSA-v3j7-r9gq-3gjw: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin re…2026-08-05
- mediumGHSA-m55f-7gqj-fr98: Electron: Extension tab APIs operate across session boundaries2026-08-05
- mediumGHSA-5c9j-mhmv-5xgx: Electron: shell.openPath path validation bypass via embedded null byte2026-08-05