← Vulnerability feed

Vulnerability record · CVE-2026-34773 · published 4 April 2026

CVE-2026-34773: Electronjs electron improper input validation vulnerability

Electronjs · Electron

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\Software\Classes\, potentially hijacking existing protocol handlers. Apps are only affected if they call app.setAsDefaultProtocolClient() with a protocol name derived from external or untrusted input. Apps that use a hardcoded protocol name are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

7.5 CVSS 3.1 High EPSS 0.27% · top 82.7% CWE-20 · Improper input validationCWE-74 · Injection
7.5CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Jul 2026Last modified by NVD

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\Software\Classes\, potentially hijacking existing protocol handlers. Apps are only affected if they call app.setAsDefaultProtocolClient() with a protocol name derived from external or untrusted input. Apps that use a hardcoded protocol name are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34773 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-4077Electronjs electron vulnerabilityIn Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…EPSS 1.0%9.8CVE-2026-34775Electronjs electron vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and…EPSS 0.37%9.8CVE-2023-23623Electronjs electron vulnerabilityElectron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disab…EPSS 0.66%9.8CVE-2022-29247Electronjs electron exposure of resource to wrong sphere vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18…EPSS 1.0%9.8CVE-2017-16151Electronjs electron code injection vulnerabilityBased on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent …EPSS 2.7%9.0CVE-2020-4076Electronjs electron vulnerabilityIn Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…EPSS 0.37%8.8CVE-2026-34765Electronjs electron exposure of resource to wrong sphere vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-a…EPSS 0.38%8.8CVE-2026-34772Electronjs electron use after free vulnerabilityElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2026-34773), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.