{"id":"GHSA-5c9j-mhmv-5xgx","summary":"Electron: shell.openPath path validation bypass via embedded null byte","details":"### Impact\n`shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation.\n\nApps are only affected if they pass paths derived from untrusted input to `shell.openPath()` and rely on string-based validation without a filesystem check. Node's `fs` APIs already reject paths containing null bytes, so apps that call `fs.existsSync()`, `fs.stat()`, or similar before `shell.openPath()` are not affected. Apps that do not call `shell.openPath()` with untrusted input are not affected.\n\n### Workarounds\nReject any path containing a null byte before passing it to `shell.openPath()`:\n```js\nif (filePath.includes('\\0')) throw new Error('invalid path');\n```\n\n### Fixed Versions\n* `42.0.0-beta.1`\n* `41.1.1`\n* `40.9.0`\n* `39.8.6`\n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)","aliases":["CVE-2026-70603"],"modified":"2026-08-05T16:11:06.665641Z","published":"2026-08-05T15:57:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-05T15:57:03Z","nvd_published_at":null,"cwe_ids":["CWE-158","CWE-20"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/electron/electron/security/advisories/GHSA-5c9j-mhmv-5xgx"},{"type":"PACKAGE","url":"https://github.com/electron/electron"}],"affected":[{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"42.0.0-alpha.1"},{"fixed":"42.0.0-beta.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-5c9j-mhmv-5xgx/GHSA-5c9j-mhmv-5xgx.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"41.0.0-alpha.1"},{"fixed":"41.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-5c9j-mhmv-5xgx/GHSA-5c9j-mhmv-5xgx.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"40.0.0-alpha.1"},{"fixed":"40.9.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-5c9j-mhmv-5xgx/GHSA-5c9j-mhmv-5xgx.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"39.8.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-5c9j-mhmv-5xgx/GHSA-5c9j-mhmv-5xgx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"}]}