<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:openjsf:electron:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aopenjsfelectron/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:19:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aopenjsfelectron/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Electron WebView Node.js Integration Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-09-electron-webview-node-integration/</link><pubDate>Tue, 29 Sep 2026 22:19:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-electron-webview-node-integration/</guid><description>A vulnerability in the Electron framework allows a &lt;webview&gt; tag to enable Node.js integration within Web Workers regardless of the embedder's restricted settings, potentially leading to unauthorized code execution.</description><content:encoded><![CDATA[<p>The Electron framework is susceptible to a privilege escalation vulnerability (CVE-2026-102676) where a <code>&lt;webview&gt;</code> tag may enable Node.js integration in its associated Web Workers, even when the parent embedder has explicitly disabled Node.js integration. This flaw creates a scenario where untrusted guest content gains unauthorized access to Node.js APIs, bypassing the security boundaries established by the parent application. The vulnerability specifically impacts applications that utilize the <code>&lt;webview&gt;</code> tag in an unsandboxed state. The lack of proper isolation between the embedder and the guest process allows for potential sandbox escapes or cross-context code execution, as the guest worker context assumes permissions that the developer intended to restrict. Defenders should prioritize auditing Electron-based applications for the use of the <code>&lt;webview&gt;</code> component and ensuring that <code>nodeIntegrationInWorker</code> is correctly managed or that the <code>sandbox</code> mode is strictly enforced.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows guest content within a <code>&lt;webview&gt;</code> to access privileged Node.js APIs that should have been disabled. This can lead to arbitrary code execution within the context of the guest process, potentially allowing an attacker to escape the intended sandbox and compromise the application or the underlying host system.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security operations teams:</p>
<ul>
<li>Patch all applications using the affected Electron versions by updating to at least 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.</li>
<li>Implement a configuration audit to identify instances where the <code>&lt;webview&gt;</code> tag is enabled, particularly when loading untrusted remote content.</li>
<li>Remove <code>nodeIntegrationInWorker</code> from guest preferences within the <code>will-attach-webview</code> handler in the application source code.</li>
<li>Enforce the use of the sandbox mode for all <code>&lt;webview&gt;</code> components to isolate guest processes from host resources.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>code-execution</category><category>framework</category></item></channel></rss>