THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f2r8-jv7c-xqmp (medium) — Electron: DevTools embedder handler executes arbitrary files via shell open

[GHSA] GHSA-f2r8-jv7c-xqmp (medium) — Electron: DevTools embedder handler executes arbitrary files via shell open

medgithub_advisoriesPublished 2026-08-05

GHSA-f2r8-jv7c-xqmp Severity: medium CVE: CVE-2026-70611

Electron: DevTools embedder handler executes arbitrary files via shell open

### Impact The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native co

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f2r8-jv7c-xqmp