CRITICAL
electerm has Command Injection Vulnerability via runLinux function
Published May 8, 2026
9.8
CRITICALCVSS 3.1
EPSS 2.49%
Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:130. The runLinux() function appends attacker-controlled remote version strings directly into an exec("rm -rf ...") command without validation. This issue has been patched in version 3.3.8.
Affected products
-
- Version < 3.3.8StatusaffectedConstraints-
- Version
- < 3.3.8
No data.
No Red Hat product state for this CVE.
electerm
npm
Introduced 0 Fixed 3.3.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electerm | 0 | 3.3.8 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28497 Advisory
- https://github.com/advisories/GHSA-8x35-hph8-37hq Advisory
- https://github.com/electerm/electerm/commit/59708b38c8a52f5db59d7d4eff98e31d573128ee x_refsource_MISCPatch
- https://github.com/electerm/electerm/releases/tag/v3.3.8 x_refsource_MISCRelease Notes
- https://github.com/electerm/electerm/security/advisories/GHSA-8x35-hph8-37hq x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41501
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28497 | Advisory | |
| https://github.com/advisories/GHSA-8x35-hph8-37hq | Advisory | |
| https://github.com/electerm/electerm/commit/59708b38c8a52f5db59d7d4eff98e31d573128ee | x_refsource_MISCPatch | |
| https://github.com/electerm/electerm/releases/tag/v3.3.8 | x_refsource_MISCRelease Notes | |
| https://github.com/electerm/electerm/security/advisories/GHSA-8x35-hph8-37hq | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41501 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 8, 2026
Updated May 8, 2026
Reserved Apr 20, 2026
Link CVE-2026-41501
CISA Vulnrichment
Updated May 8, 2026
ENISA EUVD
EUVD-2026-28497 GHSA-8X35-HPH8-37HQ Assigner GitHub_M
Published May 8, 2026
Updated May 8, 2026
Exploited since n/a
Link EUVD-2026-28497