๐Ÿ” CVE Alert

CVE-2026-34781

LOW 2.8

Electron crashes in clipboard.readImage() on malformed clipboard image data

CVSS Score
2.8
EPSS Score
0.0%
EPSS Percentile
2th

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode, the resulting null bitmap is passed unchecked to image construction, triggering a controlled abort and crashing the process. Apps are only affected if they call clipboard.readImage(). Apps that do not read images from the clipboard are not affected. This issue does not allow memory corruption or code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

CWE CWE-476
Vendor electron
Product electron
Published Apr 7, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for electron electron

Be the first to know when new low vulnerabilities affecting electron electron are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

electron / electron
< 39.8.5 >= 40.0.0-alpha.1, < 40.8.5 >= 41.0.0-alpha.1, < 41.1.0 >= 42.0.0-alpha.1, < 42.0.0-alpha.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/electron/electron/security/advisories/GHSA-f37v-82c4-4x64