CVE-2026-70607: Privileged Option Injection in Electron window.open Features
Vulnerability ID: CVE-2026-70607
CVSS Score: 5.3
Published: 2026-08-05
An input validation vulnerability in the Electron desktop framework allows untrusted web content running in a renderer process to inject privileged configuration options when creating child windows via window.open. Under Windows environments, this allows attackers to pass a remote Universal Naming Convention (UNC) path to the window icon configuration parameter, forcing the host system to make an SMB connection to a remote listener and leak the current user's NetNTLM authentication hash.
TL;DR
An input validation vulnerability in Electron's window.open features parsing allows untrusted JavaScript to control privileged browser window options. This allows attackers to force UNC path loading, leaking Windows authentication hashes via SMB.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-20
- Attack Vector: Network
- CVSS v3.1 Score: 5.3
- EPSS Score: Not Available
- Impact: Information Disclosure (NetNTLM Hash Leak)
- Exploit Status: Proof of Concept
- CISA KEV Status: Not Listed
Affected Systems
- Electron Desktop Applications running on Windows
-
electron: < 39.8.8 (Fixed in:
39.8.8) -
electron: >= 40.0.0-alpha.1, < 40.9.0 (Fixed in:
40.9.0) -
electron: >= 41.0.0-alpha.1, < 41.2.1 (Fixed in:
41.2.1) -
electron: >= 42.0.0-alpha.1, < 42.0.0-beta.3 (Fixed in:
42.0.0-beta.3)
Code Analysis
Commit: 30cf388
fix: filter window options allowed from window.open features
Commit: 4eff3dc
fix: backport window option filtering to 41.x branch
Commit: 615d625
fix: backport window option filtering to 40.x branch
Commit: fe2e7d0
fix: backport window option filtering to 39.x branch
Mitigation Strategies
- Upgrade Electron to a patched version immediately.
- Use setWindowOpenHandler to sanitize or reject client-side window options.
- Apply strict Content Security Policies to block unauthorized JavaScript execution.
Remediation Steps:
- Identify vulnerable Electron instances in package.json.
- Update Electron dependencies to 39.8.8, 40.9.0, 41.2.1, or 42.0.0-beta.3.
- Configure setWindowOpenHandler on the main process to validate and override client-supplied options.
- Validate that incoming requests cannot load remote UNC paths.
References
- GHSA-v93f-fgjr-hjrj Security Advisory
- Fix Commit 30cf3882de75ee651bd4e5f27002f13fd3d3163a
- CVE-2026-70607 Record
Read the full report for CVE-2026-70607 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)