CVE-2020-15096: Electronjs Electron

Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affected. There are no app-side workarounds, you must update your Electron version to be protected. This is fixed in versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21.

Affected products

  • Electronjs Electron: before 6.1.1 (fixed in 6.1.1); from 7.0.0, before 7.2.4 (fixed in 7.2.4); from 8.0.0, before 8.2.4 (fixed in 8.2.4); version 9.0.0 only

Published 2020-07-07. Last modified 2026-06-17.