CVE Explorer
CVE-2026-34773
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\Software\Classes\, potentially hijacking existing protocol handlers. Apps are only affected if they call ap
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-74","description":"CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"electron","vendor":"electron","versions":[{"status":"affected","version":"< 38.8.6"},{"status":"affected","version":">= 39.0.0-alpha.1, < 39.8.1"},{"status":"affected","version":">= 40.0.0-alpha.1, < 40.8.1"},{"status":"affected","version":">= 41.0.0-alpha.1, < 41.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-74","description":"CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/electron/electron/security/advisories/GHSA-mwmh-mq4g-g6gr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/electron/electron/security/advisories/GHSA-mwmh-mq4g-g6gr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:969568aa92cefb803022351d1a0cf3ee832c6df18937476c981ad27f85f3ea87 · sha256:ff5e90750faae492… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.