Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. electron
  4. ›
  5. CVE-2026-34769

CVE-2026-34769: Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

April 3, 2026 (updated April 6, 2026)

An undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls.

Apps are only affected if they construct webPreferences from external or untrusted input without an allowlist. Apps that use a fixed, hardcoded webPreferences object are not affected.

References

  • github.com/advisories/GHSA-9wfr-w7mm-pc7f
  • github.com/electron/electron
  • github.com/electron/electron/security/advisories/GHSA-9wfr-w7mm-pc7f
  • nvd.nist.gov/vuln/detail/CVE-2026-34769

Code Behaviors & Features

Detect and mitigate CVE-2026-34769 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 38.8.6, all versions starting from 39.0.0-alpha.1 before 39.8.0, all versions starting from 40.0.0-alpha.1 before 40.7.0, all versions starting from 41.0.0-alpha.1 before 41.0.0-beta.8

Fixed versions

  • 38.8.6
  • 39.8.0
  • 40.7.0
  • 41.0.0-beta.8

Solution

Upgrade to versions 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 or above.

Impact 7.7 HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
  • CWE-912: Hidden Functionality

Source file

npm/electron/CVE-2026-34769.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:18:20 +0000.