{"id":"CVE-2020-15215","aliases":["GHSA-56pc-6jqp-xqj8"],"url":"https://o3.security/vulnerability/CVE-2020-15215","summary":"Context isolation bypass in Electron","details":"Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true` are affected. This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions.","published":"2020-10-06T18:15:14.797Z","modified":"2026-08-07T11:31:23.731887370Z","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"electron","fixedVersion":"8.5.2"},{"ecosystem":"npm","name":"electron","fixedVersion":"9.3.1"},{"ecosystem":"npm","name":"electron","fixedVersion":"10.1.2"},{"ecosystem":"npm","name":"electron","fixedVersion":"11.0.0-beta.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/electron/electron/security/advisories/GHSA-56pc-6jqp-xqj8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:23.731887370Z"}}