Technology · npm
electron (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in electron (npm): 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 1 exploited in the wild. The most recent, CVE-2026-54257, was published on 23 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 2
- Exploited in the wild
- 1
About electron (npm)
A framework for building cross-platform desktop applications using JavaScript, HTML, and CSS.
Latest electron (npm) vulnerabilities
- CVE-2026-54257: Electron heap buffer overflow in Node.js Buffer APIcriticalCVSS 4EPSS 0.4%
- CVE-2026-34781: Electron denial of service in clipboard.readImagelowCVSS 3.1EPSS 0.1%
- CVE-2026-34765: Electron incorrect window scoping in window.openmediumCVSS 6EPSS 0.4%
- CVE-2026-34780: Electron context isolation bypass via VideoFrame transferhighCVSS 8.3EPSS 0.4%
- CVE-2026-34778: Electron spoofing vulnerability in executeJavaScript IPC channelmediumCVSS 5.9EPSS 0.1%
- CVE-2026-34777: Electron origin validation error in permission request handlermediumCVSS 5.4EPSS 0.1%
- CVE-2026-34775: Electron improper isolation of Node.js integration in workersmediumCVSS 6.8EPSS 0.4%
- CVE-2026-34773: Electron Registry key path injection in app.setAsDefaultProtocolClientmediumCVSS 4.7EPSS 0.3%
- CVE-2026-34772: Electron use-after-free in download save dialog callbackmediumCVSS 5.8EPSS 0.2%
- CVE-2026-34771: Electron use-after-free in permission request handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-34770: Electron use-after-free in powerMonitor modulehighCVSS 7EPSS 0.3%
- CVE-2026-34769: Electron argument injection via undocumented commandLineSwitcheshighCVSS 7.7EPSS 0.4%
- CVE-2026-34768: Electron unquoted search path in app.setLoginItemSettings on WindowslowCVSS 3.9EPSS 0.1%
- CVE-2026-34766: Electron missing authorization in select-usb-device callbacklowCVSS 3.3EPSS 0.2%
- CVE-2022-4135: Google Chrome heap buffer overflow in GPUcriticalexploited in the wildCVSS 3.1EPSS 31.9%
- CVE-2017-12581: Electron remote command execution via nodeIntegration bypasslowCVSS 3EPSS 6.7%
- CVE-2017-1000424: Electron URL spoofing in PDF viewer via PDFiumlowCVSS 3EPSS 1.0%
- CVE-2020-15215: Electron context isolation bypass via prevented window.openlowCVSS 3.1EPSS 0.7%
- CVE-2020-15174: Electron navigation bypass via cross-site sub-frame navigationlowCVSS 3.1
- CVE-2018-1000118: Electron protocol handler command injection via case-sensitive bypasslowCVSS 3EPSS 2.4%
- CVE-2016-1202: Electron untrusted search path privilege escalationlowCVSS 3EPSS 0.4%
Most severe electron (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-4135: Google Chrome heap buffer overflow in GPUcriticalexploited in the wildCVSS 3.1EPSS 31.9%
- CVE-2026-54257: Electron heap buffer overflow in Node.js Buffer APIcriticalCVSS 4EPSS 0.4%
- CVE-2026-34780: Electron context isolation bypass via VideoFrame transferhighCVSS 8.3EPSS 0.4%
- CVE-2026-34769: Electron argument injection via undocumented commandLineSwitcheshighCVSS 7.7EPSS 0.4%
- CVE-2026-34771: Electron use-after-free in permission request handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-34770: Electron use-after-free in powerMonitor modulehighCVSS 7EPSS 0.3%
- CVE-2026-34775: Electron improper isolation of Node.js integration in workersmediumCVSS 6.8EPSS 0.4%
- CVE-2026-34765: Electron incorrect window scoping in window.openmediumCVSS 6EPSS 0.4%
- CVE-2026-34778: Electron spoofing vulnerability in executeJavaScript IPC channelmediumCVSS 5.9EPSS 0.1%
- CVE-2026-34772: Electron use-after-free in download save dialog callbackmediumCVSS 5.8EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/electron.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "electron (npm) vulnerabilities", https://junglewise.ai/threats/technologies/electron, 26 September 2026.