Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9qh4-3jw8-366w | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions |
Tue, 29 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. | |
| Title | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions | |
| Weaknesses | CWE-1188 CWE-269 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T16:56:49.007Z
Reserved: 2026-09-29T16:10:04.075Z
Link: CVE-2026-102676
No data.
Status : Received
Published: 2026-09-29T17:17:07.973
Modified: 2026-09-29T17:17:07.973
Link: CVE-2026-102676
No data.
OpenCVE Enrichment
No data.
Github GHSA