← Vulnerability feed

Vulnerability record · CVE-2026-34768 · published 4 April 2026

CVE-2026-34768: Electronjs electron unquoted search path vulnerability

Electronjs · Electron

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app is installed to a path containing spaces, an attacker with write access to an ancestor directory may be able to cause a different executable to run at login instead of the intended app. On a default Windows install, standard system directories are protected against writes by standard users, so exploitation typically requires a non-standard install location. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.

7.8 CVSS 3.1 High EPSS 0.14% · top 97.3% CWE-428 · Unquoted search path
7.8CVSS 3.1 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Jul 2026Last modified by NVD

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app is installed to a path containing spaces, an attacker with write access to an ancestor directory may be able to cause a different executable to run at login instead of the intended app. On a default Windows install, standard system directories are protected against writes by standard users, so exploitation typically requires a non-standard install location. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34768 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-4077Electronjs electron vulnerabilityIn Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…EPSS 1.0%9.8CVE-2026-34775Electronjs electron vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and…EPSS 0.37%9.8CVE-2023-23623Electronjs electron vulnerabilityElectron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disab…EPSS 0.66%9.8CVE-2022-29247Electronjs electron exposure of resource to wrong sphere vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18…EPSS 1.0%9.8CVE-2017-16151Electronjs electron code injection vulnerabilityBased on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent …EPSS 2.7%9.0CVE-2020-4076Electronjs electron vulnerabilityIn Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…EPSS 0.37%8.8CVE-2026-34765Electronjs electron exposure of resource to wrong sphere vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-a…EPSS 0.38%8.8CVE-2026-34772Electronjs electron use after free vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2026-34768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.