SCA: security update for electron (GHSA-9qh4-3jw8-366w)

high Tenable Self-Hosted Container Security Plugin ID 448489

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS.
Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable
nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration
disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the
embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed
are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.
(CVE-2026-102676)

Solution

Update the electron library and its related packages to version 41.10.6 or later.

See Also

https://github.com/advisories/GHSA-9qh4-3jw8-366w

Plugin Details

Severity: High

ID: 448489

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/29/2026

Updated: 9/29/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-102676

CVSS v3

Risk Factor: High

Base Score: 8.3

Temporal Score: 7.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-102676