Sceawere
Vulnerability Detail
CVE-2026-102676UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Electron WebView NodeIntegration Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.3
- Creation Date
- 8h ago
- Vendor
- electron
- Product
- electron
- Attack Type
- CWE-269: Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.3",
"pubDate": "2026-09-29T17:17:07.973Z",
"pubdate": "2026-09-29T17:17:07.973Z",
"executiveSummary": "This vulnerability is an improper access control flaw within the Electron framework concerning the configuration of Web Workers inside <webview> tags.\nThe issue allows a malicious <webview> guest to bypass security restrictions by enabling 'nodeIntegrationInWorker' even when the parent application has explicitly disabled Node.js integration for the embedder.\nBy successfully exploiting this, an attacker can elevate their execution context, gaining access to Node.js APIs within a worker thread despite the security posture of the host application.\nThe vulnerability affects Electron versions prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.\nApplications that utilize the <webview> tag in an unsandboxed state are at the highest risk, as this configuration allows the untrusted guest content to escape the intended sandbox limitations.\nNo specific authentication is required from the attacker's perspective, provided they can execute arbitrary JavaScript within the guest content of an affected <webview> component.",
"technicalDetails": "The root cause of this vulnerability lies in an insufficient validation mechanism during the initialization of Web Workers in the <webview> component. In Electron, the <webview> tag is designed to host untrusted content in a separate process. Security policies are intended to propagate from the embedder to the guest, specifically regarding the exposure of the Node.js environment.\nTypically, when an application disables 'nodeIntegration' in the webPreferences of the embedder, the expectation is that this restriction effectively propagates to all child processes and threads, including Web Workers, created by the guest content. However, the affected versions of Electron failed to enforce this policy constraint for the 'nodeIntegrationInWorker' setting.\nThe attack flow begins when an attacker achieves cross-site scripting (XSS) or any form of arbitrary script execution within the context of a <webview> guest. Once code execution is established, the attacker can instantiate a new Web Worker. Because the underlying logic failed to verify the parent's security policy, the attacker can explicitly enable the 'nodeIntegrationInWorker' flag in the Web Worker initialization parameters.\nBy doing so, the Web Worker is spawned with access to the Node.js runtime environment. This provides the attacker with direct access to powerful Node.js modules such as 'fs' (filesystem), 'child_process' (system command execution), and 'net' (network operations), bypassing the intended sandbox restrictions placed on the guest page.\nThe exploit effectively grants the attacker higher privileges than those granted by the parent application's security policy. Once the Node-enabled worker is running, the attacker can perform arbitrary file operations, exfiltrate local data, or execute shell commands on the host machine. This represents a significant security breach, as the attacker leverages the elevated privileges of the Electron main process-based architecture via the child worker.\nThis vulnerability specifically impacts environments where <webview> is enabled and the embedder is running in an unsandboxed mode. If the embedder is sandboxed, the underlying process architecture prevents the worker from inheriting or misusing Node.js privileges in this manner, effectively mitigating the flaw."
}