A AegiFlow
MEDIUMCVSS 6.0EPSS 0.1%

CVE-2026-70603

CVE-2026-70603 updated by NVD

Published
2026-08-05
Modified
2026-09-10
EPSS percentile
1%
Sources
github-advisory, nvd

Summary

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file extension, before passing them to shell.openPath() could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation. Apps are only affected if they pass paths derived from untrusted input to shell.openPath() and rely on string-based validation without a filesystem check. This issue is fixed in versions 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmelectron42.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6

Remediation: Upgrade to 42.0.0-beta.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.