THREAT OPS › Threat News › [GHSA] GHSA-r4w5-6pfg-jxp5 (medium) — Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
[GHSA] GHSA-r4w5-6pfg-jxp5 (medium) — Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
GHSA-r4w5-6pfg-jxp5 Severity: medium CVE: CVE-2026-70606
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
### Impact When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then
Indicators of compromise
- CVE-2026-70606cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-r4w5-6pfg-jxp5