Review reviewHigh

CVE-2026-34769

electron electron, Red Hat Build of Podman Desktop, Red Hat Build of Podman Desktop - Tech Preview

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls. Apps are only affected if they construct webPreferences from external or untrusted input without an allowlis...

CVSS
8.8
EPSS
0.29%
21.8% percentile
CISA KEV
Not listed
Published
2026.04.04
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 8.8

Vulnerability overview

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow an attacker to inject switches that disable renderer sandboxing or web security controls. Apps are only affected if they construct webPreferences from external or untrusted input without an allowlis...

Affected product and versions

Product
electron electron, Red Hat Build of Podman Desktop, Red Hat Build of Podman Desktop - Tech Preview
Affected versions
>= < 38.8.6, >= >= 39.0.0-alpha.1, < 39.8.0, >= >= 40.0.0-alpha.1, < 40.7.0, >= >= 41.0.0-alpha.1, < 41.0.0-beta.8, < 38.8.6, >= 39.0.0 < 39.8.0, >= 40.0.0 < 40.7.0, 41.0.0
Fixed versions
38.8.6, 39.8.0, 40.7.0

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that electron electron, Red Hat Build of Podman Desktop, Red Hat Build of Podman Desktop - Tech Preview and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-88, CWE-912