Back to overview

CVE-2026-54257

CRITICAL
9.3
CVSS 4.0
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.

Metadata

CVE ID
CVE-2026-54257
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-06-12 17:13 UTC
Published
2026-06-23 17:08 UTC
Last updated
2026-06-23 17:47 UTC
Primary CWE
CWE-120
CWE-120: Buffer Copy without Checking Size of Input ('Classi…
Vendor / Product
electron / electron
Sources
cve.org  ·  NVD

Severity & Metrics

9.3 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
electron electron >= 42.3.1, < 42.3.3
Weakness (CWE)
CWESourceDescription
CWE-120 cna CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (1)
Back to overview