CVE-2023-39956
CVE-2023-39956 is a medium-severity vulnerability in Electronjs Electron with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- EPSS exploit prediction: 1% (45th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Electronjs Electron
- Published:
- Last modified:
Description
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if the following conditions are met: 1. The app is launched with an attacker-controlled working directory and 2. The attacker has the ability to write files to that working directory. This makes the risk quite low, in fact normally issues of this kind are considered outside of our threat model as similar to Chromium we exclude Physically Local Attacks but given the ability for this issue to bypass certain protections like ASAR Integrity it is being treated with higher importance. This issue has been fixed in versions:`26.0.0-beta.13`, `25.4.1`, `24.7.1`, `23.3.13`, and `22.3.19`. There are no app side workarounds, users must update to a patched version of Electron.
Frequently asked questions
- What is CVE-2023-39956?
- Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if the following conditions are met: 1. The app is launched with an attacker-controlled working directory and 2. The attacker has the ability to write files to that working directory. This makes the risk quite low, in fact normally issues of this kind are considered outside of our threat model as similar to Chromium we exclude Physically Local Attacks but given the ability for this issue to bypass certain protections like ASAR Integrity it is being treated with higher importance. This issue has been fixed in versions:`26.0.0-beta.13`, `25.4.1`, `24.7.1`, `23.3.13`, and `22.3.19`. There are no app side workarounds, users must update to a patched version of Electron.
- How severe is CVE-2023-39956?
- CVE-2023-39956 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is low, integrity high, and availability low.
- Is CVE-2023-39956 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (45th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-39956?
- CVE-2023-39956 primarily affects Electronjs Electron. In total, 21 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-39956?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-39956 published?
- CVE-2023-39956 was published on 2023-09-06 and last updated on 2026-06-17.
References
Affected products (21)
- cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha1:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha2:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha3:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha4:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha5:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha6:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha7:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:alpha8:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta1:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta10:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta11:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta12:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta2:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta3:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta4:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta5:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta6:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta7:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta8:*:*:*:node.js:*:*
- cpe:2.3:a:electronjs:electron:26.0.0:beta9:*:*:*:node.js:*:*
More vulnerabilities in Electronjs Electron
- CVE-2017-16151 — Critical (CVSS 9.8): Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google…
- CVE-2018-1000118 — High (CVSS 8.8): Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol…
- CVE-2026-34780 — High (CVSS 8.3): Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions…
- CVE-2026-34774 — High (CVSS 8.1): Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to…
- CVE-2018-15685 — High (CVSS 8.1): GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and…
- CVE-2018-1000136 — High (CVSS 8.1): Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values…
All CVEs affecting Electronjs Electron →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…