CVE-2020-4077

HIGH

Electron <7.2.4-9.0.0-beta21 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using both `contextIsolation` and `contextBridge` are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.electronjs.org/releases/stable?page=3#release-notes-for-v824

Scores

CVSS v3 7.7
EPSS 0.0100
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-501
Status published
Products (3)
electronjs/electron 9.0.0 (21 CPE variants)
electronjs/electron 7.0.0 - 7.2.4
npm/electron 0 - 7.2.4npm
Published Jul 07, 2020
Tracked Since Feb 18, 2026