What is CVE-2026-70604?
This CVE describes a vulnerability in Electron where custom schemes registered with supportFetchAPI but without corsEnabled were not subject to CORS enforcement. A page loaded from a remote origin could bypass restrictions and make unauthorized requests to local resources. Affected versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0 should be updated.
Azərbaycanca: Bu CVE, Electron framework-də xüsusi sxemlər (custom schemes) qeydiyyatdan keçirildikdə CORS məhdudiyyətlərinin düzgün tətbiq edilməməsi zəifliyidir. Uzaq mənbədən yüklənmiş səhifələrin local resurslara icazəsiz sorğu göndərməsinə səbəb ola bilər. 39.8.10, 40.9.3, 41.4.0 və 42.0.0 versiyalarından əvvəlki versiyalar təsirlənir, yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Electron are affected by CVE-2026-70604?
This vulnerability affects Electron versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0.
What is the main security issue described in this CVE?
The main issue is that custom schemes registered in the Electron framework are not subject to CORS enforcement, allowing pages loaded from a remote origin to make unauthorized requests to local resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.