THREAT OPS › Threat News › [GHSA] GHSA-v64r-4m7r-3mvq (medium) — Electron: HTTP redirect followed into local file loader
[GHSA] GHSA-v64r-4m7r-3mvq (medium) — Electron: HTTP redirect followed into local file loader
GHSA-v64r-4m7r-3mvq Severity: medium CVE: CVE-2026-70605
Electron: HTTP redirect followed into local file loader
### Impact When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclose
Indicators of compromise
- CVE-2026-70605cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-v64r-4m7r-3mvq