OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102676: Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions

GitHub Advisories · officialPublished Sep 29, 2026Risk 37/100

### Impact A `<webview>` could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed. Apps are only affected if they enable the `<webview>` tag and the embedder is unsandboxed. Apps that do not use `<webview>`, or that keep the embedder sandboxed, are not affected. ### Workarounds Remove `nodeIntegrationInWorker` from the guest preferences in a `will-attach-webview` handler, or do not enable the `<webview>` tag when loading untrusted content. ### Fixed Versions * `44.0.0-beta.5` * `43.4.1` * `42.9.2` * `41.10.6` ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected])

Upgrade affected packages to a patched version: electron 41.10.6, electron 42.9.2, electron 43.4.1, electron 44.0.0-beta.5.

Vendor
Not specified
Product
electron
Exploitation
none known
Evidence
official
CVSS
8.3

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source