pkg:npm/electron
48 total CVEsCRITICAL2HIGH18MEDIUM21LOW6
✅ Check your installed version
All known vulnerabilities
- >= 19.0.0, < 19.1.8
- from 0, < 22.3.25
- >= 22.0.0, < 22.3.24
- from 0, < 1.6.14
- from 0, < 1.8.2-beta5
- >= 1.7.0, < 1.7.11
- >= 39.0.0-alpha.1, < 39.8.0
- from 0, < 39.8.1
- from 0, < 1.6.8
- HIGH8.1CVE-2018-15685Electron webPreferences vulnerability can be used to perform remote code execution>= 1.7.0, < 1.7.16
- >= 1.7.0, < 1.7.13
- >= 30.0.0-alpha.1, < 30.0.5
- from 0, < 7.2.4
- from 0, < 0.33.5
- HIGH7.7CVE-2026-34769Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferencefrom 0, < 38.8.6
- from 0, < 7.2.4
- HIGH7.5CVE-2026-34771Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacksfrom 0, < 38.8.6
- HIGH7.5CVE-2023-23623Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled>= 22.0.0-beta.1, < 22.0.1
- >= 8.0.0-beta.0, < 8.5.1
- from 0, < 38.8.6
- MEDIUM6.8CVE-2026-34775Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processesfrom 0, < 38.8.6
- MEDIUM6.8CVE-2021-39184Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIfrom 0, < 11.5.0
- from 0, < 7.2.4
- from 0, < 6.1.11
- from 0, < 15.5.0
- from 0, < 38.8.6
- from 0, < 35.7.5
- from 0, < 22.3.24
- MEDIUM6.1CVE-2023-39956Electron vulnerable to out-of-package code execution when launched with arbitrary cwdfrom 0, < 22.3.19
- MEDIUM6.0CVE-2026-34765Electron: Named window.open targets not scoped to the opener's browsing contextfrom 0, < 39.8.5
- from 0, < 22.3.6
- from 0, < 38.8.6
- MEDIUM5.9CVE-2026-34767Electron: HTTP Response Header Injection in custom protocol handlers and webRequestfrom 0, < 38.8.6
- from 0, < 38.8.6
- >= 8.0.0-beta.0, < 8.5.2
- MEDIUM5.4CVE-2026-34777Electron: Incorrect origin passed to permission request handler for iframe requestsfrom 0, < 38.8.6
- from 0, < 18.3.7
- from 0, < 9.4.0
- from 0, < 38.8.6
- MEDIUM4.7CVE-2026-34773Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windowsfrom 0, < 38.8.6
- >= 1.7.0, < 1.7.6
- from 0, < 38.8.6
- LOW3.4CVE-2022-21718Renderers can obtain access to random bluetooth device without permission in Electronfrom 0, < 13.6.6
- from 0, < 38.8.6
- from 0, < 39.8.5
- >= 33.0.0-alpha.1, < 39.8.5
- LOW2.2CVE-2022-29247Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabledfrom 0, < 15.5.5
- from 0, < 28.3.2