CVE-2026-70607
medium
CVSS v3
5.3
CVSS v4 NEW
—
VIR risk
5.3
Description
Electron: window.open features string controls some window options considered privileged
Predictions
Exploit likelihood
63%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/electron/electron/commit/30cf3882de75ee651bd4e5f27002f13fd3d3163a
- https://github.com/electron/electron/commit/4eff3dc09e4d1e62d649c5ce9902f532bb7469c7
- https://github.com/electron/electron/commit/615d62500fc7732d068274b796c49487e652e90b
- https://github.com/electron/electron/commit/fe2e7d0073949b4593b624b93abf1788f5377e55
- https://github.com/electron/electron/pull/50946
- https://github.com/electron/electron/pull/50947
- https://github.com/electron/electron/pull/50948
- https://github.com/electron/electron/pull/50949
- https://github.com/electron/electron/releases/tag/v39.8.8
- https://github.com/electron/electron/releases/tag/v40.9.0
- https://github.com/electron/electron/releases/tag/v41.2.1
- https://github.com/electron/electron/releases/tag/v42.0.0-beta.3
- https://github.com/electron/electron/security/advisories/GHSA-v93f-fgjr-hjrj
- https://github.com/electron/electron
CWEs
CWE-20
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.