THREAT OPS › Threat News › [GHSA] GHSA-5c9j-mhmv-5xgx (medium) — Electron: shell.openPath path validation bypass via embedded null byte
[GHSA] GHSA-5c9j-mhmv-5xgx (medium) — Electron: shell.openPath path validation bypass via embedded null byte
GHSA-5c9j-mhmv-5xgx Severity: medium CVE: CVE-2026-70603
Electron: shell.openPath path validation bypass via embedded null byte
### Impact `shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-control
Indicators of compromise
- CVE-2026-70603cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-5c9j-mhmv-5xgx