THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5c9j-mhmv-5xgx (medium) — Electron: shell.openPath path validation bypass via embedded null byte

[GHSA] GHSA-5c9j-mhmv-5xgx (medium) — Electron: shell.openPath path validation bypass via embedded null byte

medgithub_advisoriesPublished 2026-08-05

GHSA-5c9j-mhmv-5xgx Severity: medium CVE: CVE-2026-70603

Electron: shell.openPath path validation bypass via embedded null byte

### Impact `shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-control

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5c9j-mhmv-5xgx