{"id":"GHSA-hq2x-r82h-9wj4","summary":"Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab","details":"### Impact\n\nPopups opened from a sandboxed iframe through a link (for example `target=\"_blank\"` or a middle-click) did not inherit the iframe's HTML `sandbox` restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.\n\nApps are only affected if they embed untrusted content in iframes sandboxed with `allow-scripts allow-popups`. Apps that do not embed untrusted content in sandboxed iframes are not affected.\n\n### Workarounds\n\nUse `setWindowOpenHandler` on the parent `WebContents` to deny or constrain popups opened from sandboxed frames, or do not apply `allow-popups` to sandboxed iframes that render untrusted content.\n\n### Fixed Versions\n\n* `43.0.0`\n* `42.5.2`\n* `41.10.4`\n\n### For more information\n\nIf you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)","aliases":["CVE-2026-102673"],"modified":"2026-09-29T18:15:04.710097878Z","published":"2026-09-29T18:05:34Z","database_specific":{"github_reviewed_at":"2026-09-29T18:05:34Z","nvd_published_at":null,"cwe_ids":["CWE-346","CWE-693"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4"},{"type":"WEB","url":"https://github.com/electron/electron/pull/52133"},{"type":"WEB","url":"https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba"},{"type":"WEB","url":"https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69"},{"type":"WEB","url":"https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da"},{"type":"PACKAGE","url":"https://github.com/electron/electron"},{"type":"WEB","url":"https://github.com/electron/electron/releases/tag/v41.10.4"},{"type":"WEB","url":"https://github.com/electron/electron/releases/tag/v42.5.2"},{"type":"WEB","url":"https://github.com/electron/electron/releases/tag/v43.0.0"}],"affected":[{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"41.10.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hq2x-r82h-9wj4/GHSA-hq2x-r82h-9wj4.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"42.0.0-alpha.1"},{"fixed":"42.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hq2x-r82h-9wj4/GHSA-hq2x-r82h-9wj4.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"43.0.0-alpha.1"},{"fixed":"43.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hq2x-r82h-9wj4/GHSA-hq2x-r82h-9wj4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}