OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102675: Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled

GitHub Advisories · officialPublished Sep 29, 2026Risk 37/100

### Impact Responses served through `protocol.registerFileProtocol` or `protocol.registerHttpProtocol` for a custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` could be read cross-origin by web content. This completes the fix for CVE-2026-70604. Apps are only affected if they register such a scheme, serve it through one of those handlers, and load untrusted content. Apps that set `corsEnabled: true`, or that do not load untrusted content, are not affected. ### Workarounds Set `corsEnabled: true` on the scheme, or do not load untrusted content in windows that can reach it. ### Fixed Versions * `44.0.0-beta.5` * `43.4.1` * `42.9.2` * `41.10.6` ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected])

Upgrade affected packages to a patched version: electron 41.10.6, electron 42.9.2, electron 43.4.1, electron 44.0.0-beta.5.

Vendor
Not specified
Product
electron
Exploitation
none known
Evidence
official
CVSS
7.4

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source