Electron WebView Node.js Integration Bypass
A vulnerability in the Electron framework allows a <webview> tag to enable Node.js integration within Web Workers regardless of the embedder's restricted settings, potentially leading to unauthorized code execution.
CVE search metadata
CVE search record: CVE-2026-102676. Severity: high. CVSS: 8.3. KEV: no. Product: Electron (41.10.6, 42.9.2, 43.4.1, 44.0.0-beta.5), Electron (>= 42.3.3, < 42.10.0), Electron (>= 43.0.0-beta.1, < 43.5.0), Electron (>= 44.0.0-alpha.1, < 44.0.0-beta.6). Brief: Electron WebView Node.js Integration Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-09-electron-webview-node-integration/
What's new
- 1. added coverage for Electron (>= 42.3.3, < 42.10.0) +2 products Sep 29, 22:19 via ghsa
The Electron framework is susceptible to a privilege escalation vulnerability (CVE-2026-102676) where a <webview> tag may enable Node.js integration in its associated Web Workers, even when the parent embedder has explicitly disabled Node.js integration. This flaw creates a scenario where untrusted guest content gains unauthorized access to Node.js APIs, bypassing the security boundaries established by the parent application. The vulnerability specifically impacts applications that utilize the <webview> tag in an unsandboxed state. The lack of proper isolation between the embedder and the guest process allows for potential sandbox escapes or cross-context code execution, as the guest worker context assumes permissions that the developer intended to restrict. Defenders should prioritize auditing Electron-based applications for the use of the <webview> component and ensuring that nodeIntegrationInWorker is correctly managed or that the sandbox mode is strictly enforced.
Impact
Successful exploitation allows guest content within a <webview> to access privileged Node.js APIs that should have been disabled. This can lead to arbitrary code execution within the context of the guest process, potentially allowing an attacker to escape the intended sandbox and compromise the application or the underlying host system.
Recommendation
Prioritized actions for development and security operations teams:
- Patch all applications using the affected Electron versions by updating to at least 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.
- Implement a configuration audit to identify instances where the
<webview>tag is enabled, particularly when loading untrusted remote content. - Remove
nodeIntegrationInWorkerfrom guest preferences within thewill-attach-webviewhandler in the application source code. - Enforce the use of the sandbox mode for all
<webview>components to isolate guest processes from host resources.
Immediate actions
Upgrade Electron packages to fixed versions 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.
Mitigations
Remove nodeIntegrationInWorker from guest preferences in will-attach-webview handler.
CVE-2026-102676