Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame sandbox state was also not made available to the app permission handlers, affecting apps that render untrusted content in sandboxed iframes and grant the openExternal permission by default when no setPermissionRequestHandler is installed. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
Published: 2026-08-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Electron failed to enforce sandbox restrictions when a web page requested to open an external protocol URL. If an attacker crafts a sandboxed iframe that loads a URL such as a custom protocol or mailto link, the host OS will launch the registered application regardless of the sandbox state. This flaw allows an attacker to trigger the execution of any application registered for that protocol, potentially leading to local code execution or privilege escalation on the user’s machine.

Affected Systems

The Electron framework, version 39.8.8, 40.9.0, 41.2.1, and 42.0.0‑beta.3 contain the fix; all earlier releases are affected. Users building applications with Electron before these releases could be impacted if they render untrusted content in sandboxed iframes and grant the openExternal permission implicitly.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. EPSS is unavailable and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack path is a client‑side web page loaded in an Electron application that includes sandboxed iframes containing external protocol URLs. An attacker needs only to supply such a page, and the effect is the unintended execution of an OS‑registered program. The threat is limited to systems where Electron applications render untrusted content with default openExternal permissions and lack a custom permission request handler.

Generated by OpenCVE AI on August 5, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Electron to 39.8.8 or later (40.9.0, 41.2.1, 42.0.0‑beta.3).
  • Implement a setPermissionRequestHandler to explicitly approve or deny openExternal requests for sandboxed iframes.
  • Review application logic to avoid granting the openExternal permission by default for untrusted content and consider disabling sandboxing on iframes when it is unnecessary.

Generated by OpenCVE AI on August 5, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p2rr-rvmm-c5fp Electron: Sandboxed iframes can launch external protocol handlers
History

Wed, 05 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Electron
Electron electron
Vendors & Products Electron
Electron electron

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame sandbox state was also not made available to the app permission handlers, affecting apps that render untrusted content in sandboxed iframes and grant the openExternal permission by default when no setPermissionRequestHandler is installed. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
Title Electron: Sandboxed iframes can launch external protocol handlers
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Electron Electron
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-05T19:03:29.121Z

Reserved: 2026-08-04T19:50:27.329Z

Link: CVE-2026-70612

cve-icon Vulnrichment

Updated: 2026-08-05T19:03:25.741Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T19:30:05Z

Weaknesses