SCA: security update for electron (GHSA-x8rc-wpg4-grpf)

low Tenable Cloud Security Plugin ID 445709

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS.
Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a
cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or
spoofing of trusted UI. Apps are only affected if they embed untrusted content in iframes within windows
that also display trusted UI. Apps that do not embed untrusted third-party content are not affected. This
issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3. (CVE-2026-70600)

Solution

Update the electron library and its related packages to version 39.8.8 or later.

See Also

https://github.com/advisories/GHSA-x8rc-wpg4-grpf

Plugin Details

Severity: Low

ID: 445709

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/5/2026

Updated: 8/5/2026

Risk Information

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-70600

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/5/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-70600