← Vulnerability feed

Vulnerability record · CVE-2018-1000136 · published 23 March 2018

CVE-2018-1000136: Electronjs electron improper input validation vulnerability

Electronjs · Electron

Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.

8.1 CVSS 3.0 High EPSS 5.1% · top 8.0% CWE-20 · Improper input validation
8.1CVSS 3.0 base score, v2 6.8
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1000136 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-4077Electronjs electron vulnerabilityIn Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…EPSS 1.0%9.8CVE-2026-34775Electronjs electron vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and…EPSS 0.37%9.8CVE-2023-23623Electronjs electron vulnerabilityElectron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disab…EPSS 0.66%9.8CVE-2022-29247Electronjs electron exposure of resource to wrong sphere vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18…EPSS 1.0%9.8CVE-2017-16151Electronjs electron code injection vulnerabilityBased on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent …EPSS 2.7%9.0CVE-2020-4076Electronjs electron vulnerabilityIn Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…EPSS 0.37%8.8CVE-2026-34765Electronjs electron exposure of resource to wrong sphere vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-a…EPSS 0.38%8.8CVE-2026-34772Electronjs electron use after free vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2018-1000136), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.