Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled (CVE-2026-102675)
Electron versions prior to 41.10.6, between 42.0.0-alpha.1 and 42.9.2, between 43.0.0-alpha.1 and 43.4.1, and between 44.0.0-alpha.1 and 44.0.0-beta.5 have a vulnerability where file and HTTP protocol handlers allow cross-origin reads without the corsEnabled flag. This affects apps that register custom schemes with supportFetchAPI enabled but corsEnabled disabled and load untrusted content. The vulnerability allows cross-origin reading of responses, completing a previous fix (CVE-2026-70604). Fixed versions include 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Setting corsEnabled to true or avoiding loading untrusted content mitigates the issue.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-102675) in Electron involves the improper handling of custom protocol schemes registered with protocol.registerFileProtocol or protocol.registerHttpProtocol when supportFetchAPI is true but corsEnabled is false. Under these conditions, web content can perform cross-origin reads of responses served through these handlers, potentially exposing sensitive data. The issue affects applications that register such schemes and load untrusted content. The vulnerability completes the fix for a prior issue (CVE-2026-70604). Electron has released fixed versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5 to address this problem.
Potential Impact
The vulnerability allows cross-origin reads of responses served through custom file or HTTP protocol handlers without proper CORS enforcement, potentially exposing sensitive data to unauthorized web content. Only applications that register custom schemes with supportFetchAPI enabled but corsEnabled disabled and load untrusted content are affected. Applications that set corsEnabled to true or do not load untrusted content are not impacted.
Mitigation Recommendations
A fix is available in Electron versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Users should upgrade to one of these versions or later. As a workaround, set corsEnabled to true on the custom scheme or avoid loading untrusted content in windows that can access the scheme. These mitigations prevent cross-origin reads.
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled (CVE-2026-102675)
Description
Electron versions prior to 41.10.6, between 42.0.0-alpha.1 and 42.9.2, between 43.0.0-alpha.1 and 43.4.1, and between 44.0.0-alpha.1 and 44.0.0-beta.5 have a vulnerability where file and HTTP protocol handlers allow cross-origin reads without the corsEnabled flag. This affects apps that register custom schemes with supportFetchAPI enabled but corsEnabled disabled and load untrusted content. The vulnerability allows cross-origin reading of responses, completing a previous fix (CVE-2026-70604). Fixed versions include 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Setting corsEnabled to true or avoiding loading untrusted content mitigates the issue.
CVSS v3.1
Score 7.4high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-102675) in Electron involves the improper handling of custom protocol schemes registered with protocol.registerFileProtocol or protocol.registerHttpProtocol when supportFetchAPI is true but corsEnabled is false. Under these conditions, web content can perform cross-origin reads of responses served through these handlers, potentially exposing sensitive data. The issue affects applications that register such schemes and load untrusted content. The vulnerability completes the fix for a prior issue (CVE-2026-70604). Electron has released fixed versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5 to address this problem.
Potential Impact
The vulnerability allows cross-origin reads of responses served through custom file or HTTP protocol handlers without proper CORS enforcement, potentially exposing sensitive data to unauthorized web content. Only applications that register custom schemes with supportFetchAPI enabled but corsEnabled disabled and load untrusted content are affected. Applications that set corsEnabled to true or do not load untrusted content are not impacted.
Mitigation Recommendations
A fix is available in Electron versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Users should upgrade to one of these versions or later. As a workaround, set corsEnabled to true on the custom scheme or avoid loading untrusted content in windows that can access the scheme. These mitigations prevent cross-origin reads.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j84w-jfhq-vhvj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102675"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abc27cf680226ef6846f91e
Added to database: 09/29/2026, 21:04:15 UTC
Last enriched: 09/29/2026, 21:22:23 UTC
Last updated: 09/30/2026, 03:19:45 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.