THREAT OPS › Threat News › [GHSA] GHSA-f2r8-jv7c-xqmp (medium) — Electron: DevTools embedder handler executes arbitrary files via shell open
[GHSA] GHSA-f2r8-jv7c-xqmp (medium) — Electron: DevTools embedder handler executes arbitrary files via shell open
GHSA-f2r8-jv7c-xqmp Severity: medium CVE: CVE-2026-70611
Electron: DevTools embedder handler executes arbitrary files via shell open
### Impact The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native co
Indicators of compromise
- CVE-2026-70611cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-f2r8-jv7c-xqmp