THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v3j7-r9gq-3gjw (high) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

[GHSA] GHSA-v3j7-r9gq-3gjw (high) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

medgithub_advisoriesPublished 2026-08-05

GHSA-v3j7-r9gq-3gjw Severity: high CVE: CVE-2026-70604

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

### Impact A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v3j7-r9gq-3gjw