Skip to content
Threat Feed
high advisory

Electron WebView Node.js Integration Bypass

A vulnerability in the Electron framework allows a <webview> tag to enable Node.js integration within Web Workers regardless of the embedder's restricted settings, potentially leading to unauthorized code execution.

CVE search metadata

CVE search record: CVE-2026-102676. Severity: high. CVSS: 8.3. KEV: no. Product: Electron (41.10.6, 42.9.2, 43.4.1, 44.0.0-beta.5), Electron (>= 42.3.3, < 42.10.0), Electron (>= 43.0.0-beta.1, < 43.5.0), Electron (>= 44.0.0-alpha.1, < 44.0.0-beta.6). Brief: Electron WebView Node.js Integration Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-09-electron-webview-node-integration/

What's new

  • 1. added coverage for Electron (>= 42.3.3, < 42.10.0) +2 products Sep 29, 22:19 via ghsa

The Electron framework is susceptible to a privilege escalation vulnerability (CVE-2026-102676) where a <webview> tag may enable Node.js integration in its associated Web Workers, even when the parent embedder has explicitly disabled Node.js integration. This flaw creates a scenario where untrusted guest content gains unauthorized access to Node.js APIs, bypassing the security boundaries established by the parent application. The vulnerability specifically impacts applications that utilize the <webview> tag in an unsandboxed state. The lack of proper isolation between the embedder and the guest process allows for potential sandbox escapes or cross-context code execution, as the guest worker context assumes permissions that the developer intended to restrict. Defenders should prioritize auditing Electron-based applications for the use of the <webview> component and ensuring that nodeIntegrationInWorker is correctly managed or that the sandbox mode is strictly enforced.

Impact

Successful exploitation allows guest content within a <webview> to access privileged Node.js APIs that should have been disabled. This can lead to arbitrary code execution within the context of the guest process, potentially allowing an attacker to escape the intended sandbox and compromise the application or the underlying host system.

Recommendation

Prioritized actions for development and security operations teams:

  • Patch all applications using the affected Electron versions by updating to at least 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.
  • Implement a configuration audit to identify instances where the <webview> tag is enabled, particularly when loading untrusted remote content.
  • Remove nodeIntegrationInWorker from guest preferences within the will-attach-webview handler in the application source code.
  • Enforce the use of the sandbox mode for all <webview> components to isolate guest processes from host resources.

Immediate actions

Upgrade Electron packages to fixed versions 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.

Development Team 72h

Mitigations

Remove nodeIntegrationInWorker from guest preferences in will-attach-webview handler.

immediate Development Team

CVE-2026-102676