THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r4w5-6pfg-jxp5 (medium) — Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

[GHSA] GHSA-r4w5-6pfg-jxp5 (medium) — Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

medgithub_advisoriesPublished 2026-08-05

GHSA-r4w5-6pfg-jxp5 Severity: medium CVE: CVE-2026-70606

Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

### Impact When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r4w5-6pfg-jxp5