CVE Browser
electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge
electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling
electerm: Command Injection in File System Operations (rmrf, mv, cp)
electerm's RDP clipboard file download may parse unsafe file name
Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist
electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename
Electerm check folder size function may get attacked by unsafe folder name
electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
electerm: Local code through electerm's single-instance socket
electerm's encrypt method not safe enough
electerm: dangerous code can be run through links or command line
electerm: Full process.env exposed to renderer via window.pre.env in electerm
Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
electerm: Path traversal in electerm runWidget leads to arbitrary code execution
electerm: RCE via malicious SSH server filename in openFileWithEditor
electerm has Command Injection Vulnerability via runMac function
electerm has Command Injection Vulnerability via runLinux function
An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electerms service.
Showing 1 to 19 CVEs · page 1