THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v64r-4m7r-3mvq (medium) — Electron: HTTP redirect followed into local file loader

[GHSA] GHSA-v64r-4m7r-3mvq (medium) — Electron: HTTP redirect followed into local file loader

medgithub_advisoriesPublished 2026-08-05

GHSA-v64r-4m7r-3mvq Severity: medium CVE: CVE-2026-70605

Electron: HTTP redirect followed into local file loader

### Impact When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclose

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v64r-4m7r-3mvq