Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j84w-jfhq-vhvj | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled |
Tue, 29 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. | |
| Title | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled | |
| Weaknesses | CWE-346 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T17:26:51.547Z
Reserved: 2026-09-29T16:10:04.075Z
Link: CVE-2026-102675
Updated: 2026-09-29T17:26:39.230Z
Status : Received
Published: 2026-09-29T17:17:07.813
Modified: 2026-09-29T18:17:09.457
Link: CVE-2026-102675
No data.
OpenCVE Enrichment
No data.
Github GHSA