Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions (CVE-2026-102674)
Electron versions prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5 contain a vulnerability where windows opened from a sandboxed top-level document do not inherit the document's HTML sandbox restrictions. This allows sandboxed content to open new windows with the app's full origin, potentially escalating privileges. The issue affects apps rendering untrusted content in sandboxed top-level documents that allow popups. Apps that deny popups from untrusted content using setWindowOpenHandler are not affected. Fixes are available in the specified versions.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-102674) in Electron occurs because windows opened from a sandboxed top-level document fail to inherit the sandbox restrictions defined by the HTML sandbox attribute. Consequently, content intended to be sandboxed can open new windows with the full origin privileges of the app, bypassing sandbox constraints. This issue specifically affects applications that render untrusted content in sandboxed top-level documents with popup permissions enabled. The vulnerability is addressed by returning an action to deny popups from untrusted content via setWindowOpenHandler or by upgrading to fixed Electron versions 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.
Potential Impact
This vulnerability can lead to privilege escalation where sandboxed content can escape sandbox restrictions by opening new windows with the app's full origin privileges. This undermines the security model of sandboxed content, potentially exposing sensitive data or allowing unauthorized actions within the Electron app. The impact is high due to the ability to bypass sandboxing and gain elevated privileges within the application context.
Mitigation Recommendations
A fix is available in Electron versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Users should upgrade to these or later versions to remediate the vulnerability. As a workaround, applications can return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content to prevent popup windows from bypassing sandbox restrictions.
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions (CVE-2026-102674)
Description
Electron versions prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5 contain a vulnerability where windows opened from a sandboxed top-level document do not inherit the document's HTML sandbox restrictions. This allows sandboxed content to open new windows with the app's full origin, potentially escalating privileges. The issue affects apps rendering untrusted content in sandboxed top-level documents that allow popups. Apps that deny popups from untrusted content using setWindowOpenHandler are not affected. Fixes are available in the specified versions.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-102674) in Electron occurs because windows opened from a sandboxed top-level document fail to inherit the sandbox restrictions defined by the HTML sandbox attribute. Consequently, content intended to be sandboxed can open new windows with the full origin privileges of the app, bypassing sandbox constraints. This issue specifically affects applications that render untrusted content in sandboxed top-level documents with popup permissions enabled. The vulnerability is addressed by returning an action to deny popups from untrusted content via setWindowOpenHandler or by upgrading to fixed Electron versions 41.10.6, 42.9.2, 43.4.1, or 44.0.0-beta.5.
Potential Impact
This vulnerability can lead to privilege escalation where sandboxed content can escape sandbox restrictions by opening new windows with the app's full origin privileges. This undermines the security model of sandboxed content, potentially exposing sensitive data or allowing unauthorized actions within the Electron app. The impact is high due to the ability to bypass sandboxing and gain elevated privileges within the application context.
Mitigation Recommendations
A fix is available in Electron versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Users should upgrade to these or later versions to remediate the vulnerability. As a workaround, applications can return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content to prevent popup windows from bypassing sandbox restrictions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gr2m-v5gq-v685
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102674"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abc27cf680226ef6846f91d
Added to database: 09/29/2026, 21:04:15 UTC
Last enriched: 09/29/2026, 21:22:18 UTC
Last updated: 09/30/2026, 03:19:31 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.