THREAT OPS › Threat News › [GHSA] GHSA-v3j7-r9gq-3gjw (high) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
[GHSA] GHSA-v3j7-r9gq-3gjw (high) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
GHSA-v3j7-r9gq-3gjw Severity: high CVE: CVE-2026-70604
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
### Impact A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read
Indicators of compromise
- CVE-2026-70604cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-v3j7-r9gq-3gjw