<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Electron</title>
  <link>https://cvedaily.com/pages/tags/electron.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/electron.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Electron</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45668 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45668</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45668</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type: launcher) with a #docName lab…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39310 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39310</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39310</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposin…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39309 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39309</guid>
    <pubDate>Wed, 20 May 2026 00:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39309</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunA…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26462 – Offline Hospital Management System 5.3.0 allows remote code execution due to an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26462</guid>
    <pubDate>Mon, 18 May 2026 15:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26462</strong></p>
  <p>Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system commands.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44670 – SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44670</guid>
    <pubDate>Thu, 14 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44670</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName) to embed the name in HTML before pushing to all clients via WebSocket. Three independent client paths (render.ts:120 → outerHTML, Title.ts:401 → innerHTML, tra…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44588 – SiYuan is an open-source personal knowledge management system. Prior to 3.7.0,  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44588</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44588</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0,  he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to messageElement.innerHTML in app/src/dialog/tooltip.ts:41. The encoder used at the producer side, escapeAriaLabel in app/src/util/escape.ts:19-25, only handles HTML spe…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44586 – SiYuan is an open-source personal knowledge management system. From 2.1.12 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44586</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44586</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with nodeIntegration: true and contextIsolation: false, a successful payload can call Node.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44482 – soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Las...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44482</guid>
    <pubDate>Thu, 14 May 2026 15:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44482</strong></p>
  <p>soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the user's machine. The application exposes a preload API (window.soundcloudAPI.sendTrackUpdate) to th…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-42355 – NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42355</guid>
    <pubDate>Tue, 12 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-42355</strong></p>
  <p>NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function recurse without depth limits, exhausting the thread stack and crashing the NanaZip pr…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42045 – LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42045</guid>
    <pubDate>Tue, 12 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42045</strong></p>
  <p>LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/features/Portal/Artifacts/Body/Renderer/index.tsx, if no type match is found, it will choose to call the default method, HTMLRenderer, for HTML rendering. If an attacker can induce the LLM to output content…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43899 – DeepChat is an open-source artificial intelligence agent platform that unifies m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43899</guid>
    <pubDate>Mon, 11 May 2026 23:20:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43899</strong></p>
  <p>DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). While the patch correctly restricted api.openExternal() inside the renderer's preload/index.ts script, it structurally neglected to sanitize native E…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42090 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42090</guid>
    <pubDate>Mon, 04 May 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42090</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML t…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41421 – SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41421</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41421</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast layer, and the frontend inserts it into the DOM with insertAdjacentHTML(...) at message.ts. On deskto…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40922 – SiYuan is an open-source personal knowledge management system. In versions 3.6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40922</guid>
    <pubDate>Fri, 17 Apr 2026 01:17:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40922</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTML sanitizer, but the sanitizer does not block iframe tags, and its URL-prefix blocklist does not effectively filter srcdoc attributes which contain raw HTML rather than URLs. A malicious bazaar packag…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40322 – SiYuan is an open-source personal knowledge management system. In versions 3.6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40322</guid>
    <pubDate>Thu, 16 Apr 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40322</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to survive into the rendered output. On desktop builds using Electron, windows are created with nodeIntegrat…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40107 – SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40107</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40107</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreignObject> blocks. The SVG is injected via innerHTML with no secondary sanitization. When a victim opens a note containing a malicious Mermaid diagram,…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39846 – SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39846</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39846</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextI…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34781 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34781</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34781</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode, the resulting null bitmap is passed unchecked to image construction, triggering a controlled abor…</p>
  <p><strong>CVSS:</strong> 2.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34765 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34765</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34765</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrela…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34764 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34764</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34764</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions, the release() callback provided on a paint event texture can outlive its backing native state, an…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34780 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34780</guid>
    <pubDate>Sat, 04 Apr 2026 01:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34780</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34779 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34779</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34779</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the application bundle path. Under specific conditions, a crafted launch path could lead to arbitrary AppleS…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34778 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34778</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34778</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and related methods, causing the main-process promise to resolve with attacker-controlled data. Apps are onl…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34777 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34777</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34777</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was the top-level page's origin rather than the requesting iframe's origin. Apps th…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34776 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34776</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34776</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second-instance message. Leaked memory could be delivered to the app's second-instance event handler. Thi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34775 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34775</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34775</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawned in frames configured with nodeIntegrationInWorker: false could still receive Node.js integration.…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-653</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34774 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34774</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34774</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child dereference f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34773 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34773</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34773</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrusted input as the protocol name may allow an attacker to write to arbitrary subkeys under HKCU\Softwa…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34772 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34772</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34772</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while a native save-file dialog is open for a download, dismissing the dialog dereferences freed memory,…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34771 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34771</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34771</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen, pointer-lock, or keyboard-lock permission requests. If the requesting frame navigates or the wind…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34770 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34770</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34770</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retai…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34769 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34769</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34769</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34768 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34768</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34768</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app is installed to a path containing spaces, an attacker with write access to an ancestor directory m…</p>
  <p><strong>CVSS:</strong> 3.9 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34767 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34767</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34767</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via webRequest.onHeadersReceived may be vulnerable to HTTP response header injection if attacker-controlled…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34766 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34766</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34766</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler. An app whose handler could be influenced to select a device ID outside the filtered set would gran…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34725 – DbGate is cross-platform database manager. From version 7.0.0 to before version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34725</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34725</strong></p>
  <p>DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in the Electron desktop app this can escalate to local code execution because Electron is configured with…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34585 – SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34585</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34585</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, package it as a .sy.zip, and have the victim import it through the normal Import -> SiYuan .sy.zip workfl…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34449 – SiYuan is a personal knowledge management system. Prior to version 3.6.2, a mali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34449</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34449</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via the API. The injected snippet executes in Electron's Node.js context with full OS…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34448 – SiYuan is a personal knowledge management system. Prior to version 3.6.2, an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34448</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34448</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary http(s) URLs without extensions as images, stores the attacker-controlled string in coverURL, and in…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33976 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33976</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33976</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook r…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33955 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33955</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33955</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using `dangerouslySetInnerHTML` without secure handling. When combined with the full backup and restore f…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33336 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33336</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33336</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigations. An attacker who can place a link in user-generated content (task descriptions, comments, project descriptions) can cause the BrowserWindow to na…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33335 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33335</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33335</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validation or protocol allowlisting. An attacker who can place a link with `target="_blank"` (or that otherwise triggers `window.open`) in user-generated con…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33334 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33334</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33334</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. This means any cross-site scripting (XSS) vulnerability in the Vikunja web frontend -- present or future -- automatically escalates to full remote code…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33067 – SiYuan is a personal knowledge management system. Versions 3.6.0 and below rende...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33067</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33067</strong></p>
  <p>SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject arbitrary HTML/JavaScript into these fields, which executes automatically when any user browses the Bazaar page. Because SiYuan's Electron configuration enables nodeIntegration: tru…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33066 – SiYuan is a personal knowledge management system. In versions 3.6.0 and below, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33066</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33066</strong></p>
  <p>SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through unmodified. The frontend then assigns the rendered HTML to innerHTML without any additional sanitization. A malicious package author can embed arbitrary JavaScript in their README…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32751 – SiYuan is a personal knowledge management system. In versions 3.6.0 and below, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32751</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32751</strong></p>
  <p>SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket events. The desktop version (Files.ts) properly uses escapeHtml() for the same operation. An authenticated user who can rename notebooks can inject arbitrary HTML/JavaScript that exe…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32626 – AnythingLLM is an application that turns pieces of content into context that any...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32626</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32626</strong></p>
  <p>AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS due to insecure Electron configuration. This works with default settings and requires no user interac…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5805 – Missing Authorization vulnerability in Ninetheme Electron electron allows Exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5805</guid>
    <pubDate>Thu, 22 Jan 2026 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5805</strong></p>
  <p>Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22793 – 5ire is a cross-platform desktop artificial intelligence assistant and model con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22793</guid>
    <pubDate>Wed, 21 Jan 2026 21:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22793</strong></p>
  <p>5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14498 – TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14498</guid>
    <pubDate>Tue, 23 Dec 2025 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14498</strong></p>
  <p>TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67744 – DeepChat is an open-source artificial intelligence agent platform that unifies m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67744</guid>
    <pubDate>Tue, 16 Dec 2025 01:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67744</strong></p>
  <p>DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid diagram rendering component that allows arbitrary JavaScript execution. Due to the exposure of the Electron IPC renderer to the DOM, this Cross-Site Scripting (XSS) flaw escalates to full Remote Code Execution (RCE), allow…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12843 – Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass.
This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12843</guid>
    <pubDate>Fri, 12 Dec 2025 16:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12843</strong></p>
  <p>Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66481 – DeepChat is an open-source AI chat platform that supports cloud models and LLMs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66481</guid>
    <pubDate>Tue, 09 Dec 2025 01:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66481</strong></p>
  <p>DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via th…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66222 – DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66222</guid>
    <pubDate>Wed, 03 Dec 2025 19:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66222</strong></p>
  <p>DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65026 – esm.sh is a nobuild content delivery network(CDN) for modern web development. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65026</guid>
    <pubDate>Wed, 19 Nov 2025 18:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65026</strong></p>
  <p>esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability (CWE-94) in its CSS-to-JavaScript module conversion feature. When a CSS file is requested with the ?module query parameter, esm.sh converts it to a JavaScript module by embedding the CSS content directly into a template lite…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-56800 – Reolink desktop application 8.18.12 contains a vulnerability in its local authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56800</guid>
    <pubDate>Tue, 21 Oct 2025 19:21:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-56800</strong></p>
  <p>Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript property(a.settingsManager.lockScreenPassword), an attacker can patch the return value to bypa…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55305 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55305</guid>
    <pubDate>Thu, 04 Sep 2025 23:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55305</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps with…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54871 – Electron Capture facilitates video playback for screen-sharing and capture. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54871</guid>
    <pubDate>Tue, 05 Aug 2025 01:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54871</strong></p>
  <p>Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e flag, which runs inside the main Electron context, inheriting any previously gran…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-51387 – The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-51387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-51387</guid>
    <pubDate>Mon, 04 Aug 2025 21:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-51387</strong></p>
  <p>The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-46993 – Electron is an open source framework for writing cross-platform desktop applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46993</guid>
    <pubDate>Tue, 01 Jul 2025 03:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-46993</strong></p>
  <p>Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap buffer overflow. An Electron program that uses either of the affected functions is vulnerable to a…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46992 – Electron is an open source framework for writing cross-platform desktop applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46992</guid>
    <pubDate>Tue, 01 Jul 2025 02:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46992</strong></p>
  <p>Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-57783 – The desktop application in Dot through 0.9.3 allows XSS and resultant command ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57783</guid>
    <pubDate>Mon, 02 Jun 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-57783</strong></p>
  <p>The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-48064 – GitHub Desktop is an open-source, Electron-based GitHub app designed for git dev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48064</guid>
    <pubDate>Wed, 21 May 2025 18:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-48064</strong></p>
  <p>GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share. This affects GitHub Desktop users on Windows that view malicious commits in the history view. macO…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47777 – 5ire is a cross-platform desktop artificial intelligence assistant and model con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47777</guid>
    <pubDate>Wed, 14 May 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47777</strong></p>
  <p>5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. All users of 5ire client versions prior to patched…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-35281 – An improper isolation or compartmentalization vulnerability [CWE-653] in FortiCl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35281</guid>
    <pubDate>Tue, 13 May 2025 15:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-35281</strong></p>
  <p>An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-653</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-27608 – Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27608</guid>
    <pubDate>Wed, 02 Apr 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-27608</strong></p>
  <p>Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Preferences -> Settings section of the Arduino IDE interface. In the vulnerable versions, any values ent…</p>
  <p><strong>CVSS:</strong> 1.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-57061 – An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57061</guid>
    <pubDate>Wed, 19 Mar 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-57061</strong></p>
  <p>An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23040 – GitHub Desktop is an open-source Electron-based GitHub app designed for git deve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23040</guid>
    <pubDate>Wed, 15 Jan 2025 18:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23040</strong></p>
  <p>GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform all network related operations (such as cloning, fetching, and pushing). When a…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22136 – Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22136</guid>
    <pubDate>Wed, 08 Jan 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22136</strong></p>
  <p>Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is signed with hardened runtime and lacks dangerous entitlements such as com.apple.secur…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49362 – Joplin is a free, open source note taking and to-do application. Joplin-desktop ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49362</guid>
    <pubDate>Thu, 14 Nov 2024 18:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49362</strong></p>
  <p>Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability allows the execution of untrusted HTML content within the Electron window, which…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48463 – Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48463</guid>
    <pubDate>Mon, 04 Nov 2024 21:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48463</strong></p>
  <p>Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-45835 – Mattermost Desktop App versions &lt;=5.8.0 fail to sufficiently configure Electron ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45835</guid>
    <pubDate>Mon, 16 Sep 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-45835</strong></p>
  <p>Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8258 – Improper Control of Generation of Code ('Code Injection') in Electron Fuses in L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8258</guid>
    <pubDate>Tue, 10 Sep 2024 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8258</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45621 – The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45621</guid>
    <pubDate>Mon, 02 Sep 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45621</strong></p>
  <p>The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22169 – WD Discovery
versions prior to 5.0.589 contain a misconfiguration in the Node.js...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22169</guid>
    <pubDate>Fri, 02 Aug 2024 19:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22169</strong></p>
  <p>WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresse…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39698 – electron-updater allows for automatic updates for Electron apps. The file `packa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39698</guid>
    <pubDate>Tue, 09 Jul 2024 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39698</strong></p>
  <p>electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` implements the signature validation routine for Electron applications on Windows. Because of the surrounding shell, a first pass by `cmd.exe` expands any environment variable found in command-line above. This creates a situation where `verifySignature…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-154</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23997 – Lukas Bach yana =&lt;1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23997</guid>
    <pubDate>Fri, 05 Jul 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23997</strong></p>
  <p>Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39517 – Joplin is a free, open source note taking and to-do application. A Cross site sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39517</guid>
    <pubDate>Fri, 21 Jun 2024 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39517</strong></p>
  <p>Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`) preserves `<map>` `<area>` links. However, unlike `<a>` links, the `target` and `href` attributes are not removed. Additio…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-36287 – Mattermost Desktop App versions &lt;=5.7.0 fail to disable certain Electron debug f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36287</guid>
    <pubDate>Fri, 14 Jun 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-36287</strong></p>
  <p>Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3166 – A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3166</guid>
    <pubDate>Thu, 06 Jun 2024 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3166</strong></p>
  <p>A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites into workspaces, which can be exploited to execute arbitrary JavaScript code. In the desktop application, this flaw can b…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29900 – Electron Packager bundles Electron-based application source code with a renamed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29900</guid>
    <pubDate>Fri, 29 Mar 2024 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29900</strong></p>
  <p>Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-402</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23755 – ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23755</guid>
    <pubDate>Sat, 23 Mar 2024 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23755</strong></p>
  <p>ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27303 – electron-builder is a solution to package and build a ready for distribution Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27303</guid>
    <pubDate>Wed, 06 Mar 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27303</strong></p>
  <p>electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located befo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50975 – The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50975</guid>
    <pubDate>Wed, 21 Feb 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50975</strong></p>
  <p>The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7245 – The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7245</guid>
    <pubDate>Tue, 20 Feb 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7245</strong></p>
  <p>The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1648 – electron-pdf version 20.0.0 allows an external attacker to remotely obtain

arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1648</guid>
    <pubDate>Tue, 20 Feb 2024 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1648</strong></p>
  <p>electron-pdf version 20.0.0 allows an external attacker to remotely obtain  arbitrary local files. This is possible because the application does not  validate the HTML content entered by the user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23746 – Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23746</guid>
    <pubDate>Fri, 02 Feb 2024 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23746</strong></p>
  <p>Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-23743 – Notion through 3.1.0 on macOS might allow code execution because of RunAsNode an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23743</guid>
    <pubDate>Sun, 28 Jan 2024 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-23743</strong></p>
  <p>Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21625 – SideQuest is a place to get virtual reality applications for Oculus Quest. The S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21625</guid>
    <pubDate>Thu, 04 Jan 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21625</strong></p>
  <p>SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web contents. Because, prior to version 0.10.35, the deep link URLs were not sanitized properly in all cases, a one-click remote code execution can be achieved in cases when a device is c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44402 – Electron is an open source framework for writing cross-platform desktop applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44402</guid>
    <pubDate>Fri, 01 Dec 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44402</strong></p>
  <p>Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` fuses enabled.  Apps without these fuses enabled are not impacted.  This issue is specific to macOS as these fuses are only currently supported on macOS. Specifically this issue can onl…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49314 – Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49314</guid>
    <pubDate>Tue, 28 Nov 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49314</strong></p>
  <p>Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42222 – WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog cal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42222</guid>
    <pubDate>Thu, 28 Sep 2023 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42222</strong></p>
  <p>WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39956 – Electron is a framework which lets you write cross-platform desktop applications...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39956</guid>
    <pubDate>Wed, 06 Sep 2023 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39956</strong></p>
  <p>Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted.   Specifically this issue can only be exploited if the following conditions are met: 1. The app is launched with an attacker-controlled working directory and 2. The attacker has the ability to write files to that…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-29198 – Electron is a framework which lets you write cross-platform desktop applications...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29198</guid>
    <pubDate>Wed, 06 Sep 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-29198</strong></p>
  <p>Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. This issue is only exploitable i…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23623 – Electron is a framework which lets you write cross-platform desktop applications...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23623</guid>
    <pubDate>Wed, 06 Sep 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23623</strong></p>
  <p>Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that directive, is not respected in renderers that have sandbox disabled.  i.e. `sandbox: false` in the `webPreferences` object. This allows usage of methods…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48483 – 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48483</guid>
    <pubDate>Tue, 02 May 2023 05:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48483</strong></p>
  <p>3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue exists because of an incomplete fix for CVE-2022-28005.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48482 – 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48482</guid>
    <pubDate>Tue, 02 May 2023 05:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48482</strong></p>
  <p>3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29059 – 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29059</guid>
    <pubDate>Thu, 30 Mar 2023 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29059</strong></p>
  <p>3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-1005 – A vulnerability was found in JP1016 Markdown-Electron and classified as critical...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1005</guid>
    <pubDate>Fri, 24 Feb 2023 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-1005</strong></p>
  <p>A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated re…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1005">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
