/flatpak/t3-code/
T3 Code
Early desktop GUI for AI coding agents
alpha
![]()
T3 Code is a very early MIT Electron app. This Flatpak will wrap the official Linux AppImage. It is not a vendor-official Flatpak.
T3 Code is MIT; this Flatpak is a redistribution, not vendor official.

Install
flatpak --user remote-add --if-not-exists thepeoples \
https://flatpak.thepeoples.io/thepeoples.flatpakrepo
flatpak --user install -y thepeoples io.thepeoples.T3Code
flatpak --user install -y thepeoples io.thepeoples.T3Code//0.0.37Optional system install uses sudo flatpak remote-add --if-not-exists --system and sudo flatpak install -y --system. The //version form pins the advertised ostree branch; stable tracks the latest advertised tree.
Previous versions
The remote keeps the current tree plus the last two vendor versions as extra ostree branches for rollback. Objects stay on the remote after a branch is dropped (publish does not delete).
- Version
0.0.33(ostree2c28f9b656de5904b0b1758c200b382546ed9f38314bfc4ab8003cda8f022977)
flatpak --user install -y thepeoples io.thepeoples.T3Code//0.0.33- Version
0.0.35(ostree5d7d8d8e6f67535e56a9f2d1a09ed7274369b32e756d376f071c7f1e04137d28)
flatpak --user install -y thepeoples io.thepeoples.T3Code//0.0.35Verify
- App id
io.thepeoples.T3Code, vendor T3 Tools, version0.0.37, license MIT - Channel alpha
- Download 162.1 MB · installed 500.7 MB
- sha256
ea88807ccc4b18b2c3f85726ef1235e695b656ab37c8e29c9289f7a28de336c2 - Ostree key fingerprint
98D786877B6C4E8C6889CBD2E75B1C5B0CB2D841 - Homepage https://github.com/pingdotgg/t3code
Input scan
Pinned appimage T3-Code-0.0.37-x86_64.AppImage, extracted without install scripts, scanned before wrap. 2026-09-02 14:16 UTC · trivy 0.73.0 · vuln DB 2026-09-01.
Wrap
Layers this remote adds. Gate fails on CRITICAL.
none
gate pass
Vendor
In the upstream package. Not patched here.
28 HIGH · 65 MEDIUM · 15 LOW
Vendor findings 108 · 28 HIGH · 65 MEDIUM · 15 LOW
| Severity | ID | Package | Installed | Fixed | Title |
|---|---|---|---|---|---|
| HIGH | CVE-2023-5217 | electron | 12.0.4 | 22.3.25, 24.8.5, 25.8.4, 26.2.4, 27.0.0-beta.8 | libvpx: Heap buffer overflow in vp8 encoding in libvpx |
| HIGH | CVE-2026-34769 | electron | 12.0.4 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 | Electron: Electron: Arbitrary code execution and security bypass via undocumented command-line switches |
| HIGH | CVE-2026-34769 | electron | 39.2.6 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 | Electron: Electron: Arbitrary code execution and security bypass via undocumented command-line switches |
| HIGH | CVE-2026-34770 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8 | Electron: Use-after-free in PowerMonitor on Windows and macOS |
| HIGH | CVE-2026-34770 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8 | Electron: Use-after-free in PowerMonitor on Windows and macOS |
| HIGH | CVE-2026-34771 | electron | 12.0.4 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 | electron: Electron: Memory corruption or application crash via use-after-free in permission request handling |
| HIGH | CVE-2026-34771 | electron | 39.2.6 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 | electron: Electron: Memory corruption or application crash via use-after-free in permission request handling |
| HIGH | CVE-2026-34774 | electron | 12.0.4 | 39.8.1, 40.7.0, 41.0.0 | Electron: Electron: Memory corruption and crash due to use-after-free in offscreen rendering |
| HIGH | CVE-2026-34774 | electron | 39.2.6 | 39.8.1, 40.7.0, 41.0.0 | Electron: Electron: Memory corruption and crash due to use-after-free in offscreen rendering |
| HIGH | CVE-2026-34780 | electron | 39.2.6 | 39.8.0, 40.7.0, 41.0.0-beta.8 | electron: Electron: Context Isolation bypass via VideoFrame object transfer |
| HIGH | CVE-2026-70601 | electron | 12.0.4 | 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5 | Electron: Context isolation bypass via Function.prototype.bind hijack |
| HIGH | CVE-2026-70601 | electron | 39.2.6 | 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5 | Electron: Context isolation bypass via Function.prototype.bind hijack |
| HIGH | CVE-2026-70601 | electron | 39.8.5 | 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.5 | Electron: Context isolation bypass via Function.prototype.bind hijack |
| HIGH | CVE-2026-70604 | electron | 12.0.4 | 42.0.0, 41.4.0, 40.9.3, 39.8.10 | Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads |
| HIGH | CVE-2026-70604 | electron | 39.2.6 | 42.0.0, 41.4.0, 40.9.3, 39.8.10 | Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads |
| HIGH | CVE-2026-70604 | electron | 39.8.5 | 42.0.0, 41.4.0, 40.9.3, 39.8.10 | Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads |
| HIGH | CVE-2026-70608 | electron | 12.0.4 | 42.0.1, 41.10.3, 39.8.10 | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path |
| HIGH | CVE-2026-70608 | electron | 39.2.6 | 42.0.1, 41.10.3, 39.8.10 | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path |
| HIGH | CVE-2026-70608 | electron | 39.8.5 | 42.0.1, 41.10.3, 39.8.10 | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path |
| HIGH | CVE-2026-13676 | fast-uri | 3.0.1 | 4.0.1, 3.1.3, 2.4.2 | fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization |
| HIGH | CVE-2026-16221 | fast-uri | 3.0.1 | 2.4.3, 3.1.4, 4.1.1 | fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency |
| HIGH | CVE-2026-18446 | fast-uri | 3.0.1 | 2.4.4, 3.1.5, 4.1.2 | fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority |
| HIGH | CVE-2026-6321 | fast-uri | 3.0.1 | 3.1.1, 2.4.1 | fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies |
| HIGH | CVE-2026-6322 | fast-uri | 3.0.1 | 3.1.2, 2.4.1 | fast-uri: fast-uri: URI authority bypass due to improper delimiter handling |
| HIGH | CVE-2026-59869 | js-yaml | 4.1.0 | 3.15.0, 4.3.0 | js-yaml: js-yaml: Denial of Service via crafted YAML documents |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.1.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported |
| HIGH | CVE-2022-25883 | semver | 7.3.5 | 7.5.2, 6.3.1, 5.7.2 | nodejs-semver: Regular expression denial of service |
| HIGH | CVE-2026-13697 | undici | 8.7.0 | 7.29.0, 8.9.0 | undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives |
| MEDIUM | CVE-2025-69873 | ajv | 8.0.0 | 8.18.0, 6.14.0 | ajv: ReDoS via $data reference |
| MEDIUM | CVE-2025-69873 | ajv | 8.6.3 | 8.18.0, 6.14.0 | ajv: ReDoS via $data reference |
| MEDIUM | CVE-2021-39184 | electron | 12.0.4 | 11.5.0, 12.1.0, 13.3.0 | Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API |
| MEDIUM | CVE-2022-29257 | electron | 12.0.4 | 15.5.0, 16.2.0, 17.2.0, 18.0.0-beta.6 | AutoUpdater module fails to validate certain nested components of the bundle |
| MEDIUM | CVE-2022-36077 | electron | 12.0.4 | 18.3.7, 20.0.1, 19.0.11 | Electron: Redirection error and misuse of hashed credentials |
| MEDIUM | CVE-2023-29198 | electron | 12.0.4 | 22.3.6, 23.2.3, 24.0.1, 25.0.0-alpha.2 | Electron context isolation bypass via nested unserializable return value |
| MEDIUM | CVE-2023-39956 | electron | 12.0.4 | 22.3.19, 23.3.13, 24.7.1, 25.5.0, 26.0.0-beta.13 | Electron vulnerable to out-of-package code execution when launched with arbitrary cwd |
| MEDIUM | CVE-2023-44402 | electron | 12.0.4 | 22.3.24, 24.8.3, 25.8.1, 26.2.1, 27.0.0-alpha.7 | ASAR Integrity bypass via filetype confusion in electron |
| MEDIUM | CVE-2024-46993 | electron | 12.0.4 | 28.3.2, 29.3.3, 30.0.3 | Electron vulnerable to Heap Buffer Overflow in NativeImage |
| MEDIUM | CVE-2025-55305 | electron | 12.0.4 | 35.7.5, 36.8.1, 37.3.1, 38.0.0-beta.6 | electron: ASAR Integrity Bypass via resource modification |
| MEDIUM | CVE-2026-34765 | electron | 12.0.4 | 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5 | electron: Electron: Arbitrary code execution or information disclosure via incorrect window handling |
| MEDIUM | CVE-2026-34765 | electron | 39.2.6 | 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5 | electron: Electron: Arbitrary code execution or information disclosure via incorrect window handling |
| MEDIUM | CVE-2026-34767 | electron | 12.0.4 | 38.8.6, 39.8.3, 40.8.3, 41.0.3 | electron: Electron: HTTP Response Header Injection via attacker-controlled input |
| MEDIUM | CVE-2026-34767 | electron | 39.2.6 | 38.8.6, 39.8.3, 40.8.3, 41.0.3 | electron: Electron: HTTP Response Header Injection via attacker-controlled input |
| MEDIUM | CVE-2026-34772 | electron | 12.0.4 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.7 | Electron: Electron: Use-after-free vulnerability leads to memory corruption or crash |
| MEDIUM | CVE-2026-34772 | electron | 39.2.6 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.7 | Electron: Electron: Use-after-free vulnerability leads to memory corruption or crash |
| MEDIUM | CVE-2026-34773 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | electron: Electron: Protocol handler hijacking via improper validation of protocol names |
| MEDIUM | CVE-2026-34773 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | electron: Electron: Protocol handler hijacking via improper validation of protocol names |
| MEDIUM | CVE-2026-34775 | electron | 12.0.4 | 38.8.6, 39.8.4, 40.8.4, 41.0.0 | Electron: Electron: Arbitrary code execution and information disclosure due to incorrect Node.js integration scoping |
| MEDIUM | CVE-2026-34775 | electron | 39.2.6 | 38.8.6, 39.8.4, 40.8.4, 41.0.0 | Electron: Electron: Arbitrary code execution and information disclosure due to incorrect Node.js integration scoping |
| MEDIUM | CVE-2026-34776 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | Electron: Electron: Information disclosure via crafted second-instance message |
| MEDIUM | CVE-2026-34776 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | Electron: Electron: Information disclosure via crafted second-instance message |
| MEDIUM | CVE-2026-34777 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | Electron: Electron: Unauthorized permission granting and information disclosure via incorrect iframe origin |
| MEDIUM | CVE-2026-34777 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | Electron: Electron: Unauthorized permission granting and information disclosure via incorrect iframe origin |
| MEDIUM | CVE-2026-34778 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | Electron: Electron: Integrity issue due to IPC channel spoofing by a service worker |
| MEDIUM | CVE-2026-34778 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.1, 41.0.0 | Electron: Electron: Integrity issue due to IPC channel spoofing by a service worker |
| MEDIUM | CVE-2026-34779 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8 | Electron: AppleScript injection in app.moveToApplicationsFolder on macOS |
| MEDIUM | CVE-2026-34779 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8 | Electron: AppleScript injection in app.moveToApplicationsFolder on macOS |
| MEDIUM | CVE-2026-70597 | electron | 12.0.4 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: Parent process code-sign check is spoofable |
| MEDIUM | CVE-2026-70597 | electron | 39.2.6 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: Parent process code-sign check is spoofable |
| MEDIUM | CVE-2026-70597 | electron | 39.8.5 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: Parent process code-sign check is spoofable |
| MEDIUM | CVE-2026-70599 | electron | 12.0.4 | 39.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1 | Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin |
| MEDIUM | CVE-2026-70599 | electron | 39.2.6 | 39.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1 | Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin |
| MEDIUM | CVE-2026-70599 | electron | 39.8.5 | 39.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1 | Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin |
| MEDIUM | CVE-2026-70602 | electron | 12.0.4 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Extension tab APIs operate across session boundaries |
| MEDIUM | CVE-2026-70602 | electron | 39.2.6 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Extension tab APIs operate across session boundaries |
| MEDIUM | CVE-2026-70602 | electron | 39.8.5 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Extension tab APIs operate across session boundaries |
| MEDIUM | CVE-2026-70603 | electron | 12.0.4 | 42.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6 | Electron: shell.openPath path validation bypass via embedded null byte |
| MEDIUM | CVE-2026-70603 | electron | 39.2.6 | 42.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6 | Electron: shell.openPath path validation bypass via embedded null byte |
| MEDIUM | CVE-2026-70603 | electron | 39.8.5 | 42.0.0-beta.1, 41.1.1, 40.9.0, 39.8.6 | Electron: shell.openPath path validation bypass via embedded null byte |
| MEDIUM | CVE-2026-70605 | electron | 12.0.4 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: HTTP redirect followed into local file loader |
| MEDIUM | CVE-2026-70605 | electron | 39.2.6 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: HTTP redirect followed into local file loader |
| MEDIUM | CVE-2026-70605 | electron | 39.8.5 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: HTTP redirect followed into local file loader |
| MEDIUM | CVE-2026-70607 | electron | 12.0.4 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: window.open features string controls some window options considered privileged |
| MEDIUM | CVE-2026-70607 | electron | 39.2.6 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: window.open features string controls some window options considered privileged |
| MEDIUM | CVE-2026-70607 | electron | 39.8.5 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: window.open features string controls some window options considered privileged |
| MEDIUM | CVE-2026-70609 | electron | 12.0.4 | 39.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1 | Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter |
| MEDIUM | CVE-2026-70609 | electron | 39.2.6 | 39.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1 | Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter |
| MEDIUM | CVE-2026-70609 | electron | 39.8.5 | 39.8.7, 40.9.0, 41.2.0, 42.0.0-beta.1 | Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter |
| MEDIUM | CVE-2026-70610 | electron | 12.0.4 | 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.4 | Electron: contextBridge object copy honors prototype setters |
| MEDIUM | CVE-2026-70610 | electron | 39.2.6 | 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.4 | Electron: contextBridge object copy honors prototype setters |
| MEDIUM | CVE-2026-70610 | electron | 39.8.5 | 39.8.9, 40.9.2, 41.2.2, 42.0.0-beta.4 | Electron: contextBridge object copy honors prototype setters |
| MEDIUM | CVE-2026-70611 | electron | 12.0.4 | 39.8.9, 40.9.2, 41.2.1, 42.0.0-beta.3 | Electron: DevTools embedder handler executes arbitrary files via shell open |
| MEDIUM | CVE-2026-70611 | electron | 39.2.6 | 39.8.9, 40.9.2, 41.2.1, 42.0.0-beta.3 | Electron: DevTools embedder handler executes arbitrary files via shell open |
| MEDIUM | CVE-2026-70611 | electron | 39.8.5 | 39.8.9, 40.9.2, 41.2.1, 42.0.0-beta.3 | Electron: DevTools embedder handler executes arbitrary files via shell open |
| MEDIUM | CVE-2026-70612 | electron | 12.0.4 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Sandboxed iframes can launch external protocol handlers |
| MEDIUM | CVE-2026-70612 | electron | 39.2.6 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Sandboxed iframes can launch external protocol handlers |
| MEDIUM | CVE-2026-70612 | electron | 39.8.5 | 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Sandboxed iframes can launch external protocol handlers |
| MEDIUM | CVE-2025-64718 | js-yaml | 4.1.0 | 4.1.1, 3.14.2 | js-yaml: js-yaml prototype pollution in merge |
| MEDIUM | CVE-2026-53550 | js-yaml | 4.1.0 | 4.2.0, 3.15.0 | js-yaml: js-yaml: Denial of Service via crafted YAML merge keys |
| MEDIUM | CVE-2025-66400 | mdast-util-to-hast | 13.0.0 | 13.2.1 | mdast-util-to-hast: mdast-util-to-hast: Markdown code elements can appear as regular page content |
| MEDIUM | CVE-2026-14643 | undici | 8.7.0 | 7.29.0, 8.9.0 | undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing |
| MEDIUM | CVE-2026-15157 | undici | 8.7.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| MEDIUM | CVE-2026-16728 | undici | 8.7.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| MEDIUM | CVE-2026-16729 | undici | 8.7.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| LOW | CVE-2022-21718 | electron | 12.0.4 | 13.6.6, 14.2.4, 15.3.5, 16.0.6, 17.0.0-alpha.6 | Renderers can obtain access to random bluetooth device without permission in Electron |
| LOW | CVE-2022-29247 | electron | 12.0.4 | 15.5.5, 16.2.6, 17.2.0, 18.0.0-beta.6 | Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled |
| LOW | CVE-2026-34764 | electron | 39.2.6 | 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5 | Electron: Electron: Memory corruption or crash due to use-after-free in offscreen rendering with shared textures. |
| LOW | CVE-2026-34766 | electron | 12.0.4 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 | Electron: Electron: Unauthorized USB device access via select-usb-device event callback validation bypass |
| LOW | CVE-2026-34766 | electron | 39.2.6 | 38.8.6, 39.8.0, 40.7.0, 41.0.0-beta.8 | Electron: Electron: Unauthorized USB device access via select-usb-device event callback validation bypass |
| LOW | CVE-2026-34768 | electron | 12.0.4 | 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8 | electron: Electron: Arbitrary code execution via unquoted path in Run registry key |
| LOW | CVE-2026-34768 | electron | 39.2.6 | 38.8.6, 39.8.1, 40.8.0, 41.0.0-beta.8 | electron: Electron: Arbitrary code execution via unquoted path in Run registry key |
| LOW | CVE-2026-34781 | electron | 12.0.4 | 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5 | Electron: Electron: Denial of Service via malformed clipboard image data |
| LOW | CVE-2026-34781 | electron | 39.2.6 | 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5 | Electron: Electron: Denial of Service via malformed clipboard image data |
| LOW | CVE-2026-70598 | electron | 12.0.4 | 39.8.10, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size |
| LOW | CVE-2026-70598 | electron | 39.2.6 | 39.8.10, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size |
| LOW | CVE-2026-70598 | electron | 39.8.5 | 39.8.10, 40.9.0, 41.2.1, 42.0.0-beta.3 | Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size |
| LOW | CVE-2026-70600 | electron | 12.0.4 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: Cross-origin iframe can position native autofill popup |
| LOW | CVE-2026-70600 | electron | 39.2.6 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: Cross-origin iframe can position native autofill popup |
| LOW | CVE-2026-70600 | electron | 39.8.5 | 39.8.8, 40.9.1, 41.2.1, 42.0.0-beta.3 | Electron: Cross-origin iframe can position native autofill popup |
Previous scans
Daily Trivy refresh. Current report plus the last 14 full scans; older copies are deleted.
| Scanned | Vuln DB | Version | Wrap | Vendor | Report |
|---|---|---|---|---|---|
| 2026-09-02 14:02 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-02 06:51 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-02 04:58 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-02 04:31 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-02 03:57 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-02 03:44 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-02 01:42 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-01 07:28 UTC | 2026-09-01 | 0.0.37 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-09-01 06:51 UTC | 2026-09-01 | 0.0.36 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-08-31 09:28 UTC | 2026-08-31 | 0.0.36 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-08-31 07:28 UTC | 2026-08-31 | 0.0.36 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-08-31 06:51 UTC | 2026-08-31 | 0.0.36 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-08-30 07:29 UTC | 2026-08-30 | 0.0.36 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |
| 2026-08-30 06:51 UTC | 2026-08-30 | 0.0.35 | none | 28 HIGH · 65 MEDIUM · 15 LOW | JSON |