THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4f78-qhmw-8j8m (medium) — Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

[GHSA] GHSA-4f78-qhmw-8j8m (medium) — Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

medgithub_advisoriesPublished 2026-08-05

GHSA-4f78-qhmw-8j8m Severity: medium CVE: CVE-2026-70609

Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

### Impact The `mode` option of `webContents.openDevTools()` was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4f78-qhmw-8j8m