CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70607

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-08-05
Impact Some window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths. Apps are only affected if untrusted content can call window.open() and the app does not override child window options via setWindowOpenHandler. Apps that deny window.open() for untrusted content, or set overrideBrowserWindowOptions explicitly, are not affected. Workarounds Return { action: 'deny' } from setWindowOpenHandler for untrusted content, or supply overrideBrowserWindowOptions so every window option is set explicitly. Fixed Versions - 42.0.0-beta.3 - 41.2.1 - 40.9.0 - 39.8.8 For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org

⚡ Watch CVE-2026-70607

Get an email if CVE-2026-70607 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-70607

CVE.org record

Embed the live status

CVE-2026-70607 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70607 status](https://www.csirts.com/badge/CVE-2026-70607)](https://www.csirts.com/cve/CVE-2026-70607)