Junglewise Threat Intelligence

CVE-2026-34773: Electron Registry key path injection in app.setAsDefaultProtocolClient

CVE-2026-34773 · Severity: medium · CVSS 4.7 · Published 2026-04-04

Technologies: ElectronJS Electron.

Executive brief

Electron is a popular framework used to build desktop applications like Slack, Discord, and VS Code. A security flaw on Windows allows an attacker to manipulate how the computer handles specific file types or web links if the application doesn't properly check the names it uses. This could allow an attacker to hijack existing system shortcuts or redirect users to malicious software, though it requires the application to be specifically designed to accept external input for these settings.

Technical details

A registry key path injection vulnerability exists in Electron's 'app.setAsDefaultProtocolClient' API on Windows. The root cause is improper neutralization of special elements (CWE-74) and improper input validation (CWE-20) of the protocol name string before it is written to the Windows Registry. An attacker who can influence the input passed to this function can write to arbitrary subkeys under 'HKCU\Software\Classes\', enabling the hijacking of existing protocol handlers. This exploit requires the target application to derive the protocol name from untrusted or external input. The issue is patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

Affected products

  • ElectronJS Electron < 38.8.6, >= 39.0.0-alpha.1 < 39.8.1, >= 40.0.0-alpha.1 < 40.8.1, >= 41.0.0-alpha.1 < 41.0.0

Timeline

  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-04: disclosed: CVE published to NVD

References