CVE-2026-70605
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
electronnpm | < 39.8.8 | 39.8.8 |
electronnpm | >= 40.0.0-alpha.1, < 40.9.1 | 40.9.1 |
electronnpm | >= 41.0.0-alpha.1, < 41.2.1 | 41.2.1 |
electronnpm | >= 42.0.0-alpha.1, < 42.0.0-beta.3 | 42.0.0-beta.3 |
Affected products
1- Range: >=39.8.8, >=40.9.0, >=41.2.1, >=42.0.0-beta.3
Patches
Vulnerability mechanics
References
2News mentions
1- Electron Framework: 16 Vulnerabilities Disclosed, Including Sandbox Bypass and Prototype PollutionVypr Intelligence · Aug 5, 2026