{"id":"CVE-2020-15174","aliases":["GHSA-2q4g-w47c-4674"],"url":"https://o3.security/vulnerability/CVE-2020-15174","summary":"Unpreventable top-level navigation","details":"In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navigation across sites. The issue is patched in versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 As a workaround sandbox all your iframes using the sandbox attribute. This will prevent them creating top-frame navigations and is good practice anyway.","published":"2020-10-06T18:15:14.283Z","modified":"2026-08-07T15:11:47.059866Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"electron","fixedVersion":"8.5.1"},{"ecosystem":"npm","name":"electron","fixedVersion":"9.3.0"},{"ecosystem":"npm","name":"electron","fixedVersion":"10.0.1"}],"fix":{"url":"https://github.com/electron/electron/commit/18613925610ba319da7f497b6deed85ad712c59b","label":"electron/electron@1861392"},"references":[{"type":"ADVISORY","url":"https://github.com/electron/electron/security/advisories/GHSA-2q4g-w47c-4674"},{"type":"FIX","url":"https://github.com/electron/electron/commit/18613925610ba319da7f497b6deed85ad712c59b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:11:47.059866Z"}}