CVE-2026-34778 | Electron up to 38.8.5/39.8.0/40.8.0/40.x Reply Message webContents.executeJavaScript authentication spoofing (GHSA-xj5x-m3f3-5x3h)
A vulnerability marked as critical has been reported in Electron up to 38.8.5/39.8.0/40.8.0/40.x. Affected is the function webContents.executeJavaScript of the component Reply Message Handler. Performing a manipulation results in authentication bypass by spoofing.
This vulnerability was named CVE-2026-34778. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.