CVE-2026-34779 | Electron up to 38.8.5/39.8.0/40.7.x on macOS app.moveToApplicationsFolder os command injection (GHSA-5rqw-r77c-jp79)
A vulnerability was found in Electron up to 38.8.5/39.8.0/40.7.x on macOS. It has been rated as critical. This vulnerability affects the function app.moveToApplicationsFolder. Performing a manipulation results in os command injection.
This vulnerability is known as CVE-2026-34779. Attacking locally is a requirement. No exploit is available.
Upgrading the affected component is advised.