CVE-2020-4076

HIGH

Electron <9.0.0-beta21-<8.2.4-<7.2.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using contextIsolation are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.electronjs.org/releases/stable?page=3#release-notes-for-v824

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 29.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-501
Status published
Products (3)
electronjs/electron 9.0.0 (21 CPE variants)
electronjs/electron 7.0.0 - 7.2.4
npm/electron 0 - 7.2.4npm
Published Jul 07, 2020
Tracked Since Feb 18, 2026