DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-70607: CVE-2026-70607: Privileged Option Injection in Electron window.open Features

CVE-2026-70607: Privileged Option Injection in Electron window.open Features

Vulnerability ID: CVE-2026-70607
CVSS Score: 5.3
Published: 2026-08-05

An input validation vulnerability in the Electron desktop framework allows untrusted web content running in a renderer process to inject privileged configuration options when creating child windows via window.open. Under Windows environments, this allows attackers to pass a remote Universal Naming Convention (UNC) path to the window icon configuration parameter, forcing the host system to make an SMB connection to a remote listener and leak the current user's NetNTLM authentication hash.

TL;DR

An input validation vulnerability in Electron's window.open features parsing allows untrusted JavaScript to control privileged browser window options. This allows attackers to force UNC path loading, leaking Windows authentication hashes via SMB.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-20
  • Attack Vector: Network
  • CVSS v3.1 Score: 5.3
  • EPSS Score: Not Available
  • Impact: Information Disclosure (NetNTLM Hash Leak)
  • Exploit Status: Proof of Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • Electron Desktop Applications running on Windows
  • electron: < 39.8.8 (Fixed in: 39.8.8)
  • electron: >= 40.0.0-alpha.1, < 40.9.0 (Fixed in: 40.9.0)
  • electron: >= 41.0.0-alpha.1, < 41.2.1 (Fixed in: 41.2.1)
  • electron: >= 42.0.0-alpha.1, < 42.0.0-beta.3 (Fixed in: 42.0.0-beta.3)

Code Analysis

Commit: 30cf388

fix: filter window options allowed from window.open features

Commit: 4eff3dc

fix: backport window option filtering to 41.x branch

Commit: 615d625

fix: backport window option filtering to 40.x branch

Commit: fe2e7d0

fix: backport window option filtering to 39.x branch

Mitigation Strategies

  • Upgrade Electron to a patched version immediately.
  • Use setWindowOpenHandler to sanitize or reject client-side window options.
  • Apply strict Content Security Policies to block unauthorized JavaScript execution.

Remediation Steps:

  1. Identify vulnerable Electron instances in package.json.
  2. Update Electron dependencies to 39.8.8, 40.9.0, 41.2.1, or 42.0.0-beta.3.
  3. Configure setWindowOpenHandler on the main process to validate and override client-supplied options.
  4. Validate that incoming requests cannot load remote UNC paths.

References


Read the full report for CVE-2026-70607 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)