CVE-2026-34779

EUVD-2026-18957
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the application bundle path. Under specific conditions, a crafted launch path could lead to arbitrary AppleScript execution when the user accepted the move-to-Applications prompt. Apps are only affected if they call app.moveToApplicationsFolder(). Apps that do not use this API are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
electronjselectron
𝑥
< 38.8.6
electronjselectron
39.0.0 ≤
𝑥
< 39.8.1
electronjselectron
40.0.0 ≤
𝑥
< 40.8.0
electronjselectron
41.0.0:alpha1
electronjselectron
41.0.0:alpha2
electronjselectron
41.0.0:alpha3
electronjselectron
41.0.0:alpha4
electronjselectron
41.0.0:alpha5
electronjselectron
41.0.0:alpha6
electronjselectron
41.0.0:beta1
electronjselectron
41.0.0:beta2
electronjselectron
41.0.0:beta3
electronjselectron
41.0.0:beta4
electronjselectron
41.0.0:beta5
electronjselectron
41.0.0:beta6
electronjselectron
41.0.0:beta7
𝑥
= Vulnerable software versions