Résumé
Electron: Sandboxed iframes can launch external protocol handlers
Détails de l’avis
Impact
Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app's permission handlers.
Apps are only affected if they render untrusted content in sandboxed iframes and grant the openExternal permission (granted by default when no setPermissionRequestHandler is installed). Apps whose permission handler denies openExternal for untrusted content are not affected.
Workarounds
Install a setPermissionRequestHandler that denies the openExternal permission for untrusted content.
Fixed Versions
42.0.0-beta.341.2.140.9.039.8.8
For more information
If you have any questions or comments about this advisory, email Electron at security@electronjs.org
Références
- https://github.com/advisories/GHSA-p2rr-rvmm-c5fp
- https://github.com/electron/electron/security/advisories/GHSA-p2rr-rvmm-c5fp
- https://github.com/electron/electron/pull/50961
- https://github.com/electron/electron/pull/50962
- https://github.com/electron/electron/pull/50963
- https://github.com/electron/electron/pull/50964
- https://github.com/electron/electron/commit/08b9d0a220e267d1a2402a44bdd01a2e9aa320b5
- https://github.com/electron/electron/commit/2764e4c35168855f614876051823db4f58a3714a
Vulnérabilités liées
Tout Supply chain →- MEDIUMCVE-2026-55678
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
- HIGHCVE-2026-55622
Incus has a project restriction bypass in instance copy across projects
- HIGHCVE-2026-55621
Incus has a project restriction bypass for custom volume copy across projects
- MEDIUMCVE-2026-55548
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
- CRITICALCVE-2026-55536
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
- MEDIUMCVE-2026-54256
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata