A vulnerability tracked as CVE-2026-70609 was disclosed in Electron, where an unsanitized dock-state parameter could allow JavaScript injection into Electron DevTools under the conditions described in the advisory. Public reporting said the issue was fixed by Electron, and the CVE record and upstream advisory were cited as corroborating both the flaw and its remediation.
The issue appeared alongside broader vulnerability tracking in Striga’s CVE roundup, which listed multiple high- and critical-severity flaws across products including n8n, FreshRSS, Apache httpd, Apache Shiro, Apache Tomcat, axios, and Mattermost Desktop. Separate reporting noted that while Striga attributed discovery of the Electron flaw to an AI system, upstream records credited a human reporter and did not independently confirm the AI attribution.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Striga's public tracker attributed CVE-2026-70609 to an AI system, while the upstream Electron advisory and CVE record credited a human reporter instead. The reference notes that this AI attribution was not independently confirmed by upstream sources.
CVE-2026-70609 was recorded as an Electron vulnerability involving an unsanitized dock-state parameter that could allow JavaScript injection into Electron DevTools under the advisory's conditions. The reference says Electron published a public security advisory, the CVE record corroborates the issue, and the vulnerability was fixed.
A vulnerability roundup lists multiple 2026 CVEs affecting products including Logseq, Apache httpd, Apache Shiro, Apple container, Ollama, pac4j, Apache Tomcat, axios, n8n, Mattermost Desktop, and OpenClaw, with severities ranging from Low to Critical. The roundup includes writeup links for some entries but does not anchor individual disclosure dates.
A vulnerability roundup lists CVE-2025-68932 affecting FreshRSS with Critical severity and a CVSS score of 9.8. The reference provides no explicit disclosure date beyond the CVE year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.