Electerm
Electerm · 19 CVEs
electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge
Sep 8, 2026
electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling
Aug 19, 2026
electerm: Command Injection in File System Operations (rmrf, mv, cp)
Aug 19, 2026
electerm's RDP clipboard file download may parse unsafe file name
Aug 11, 2026
Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-na…
Aug 11, 2026
electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename
Aug 11, 2026
Electerm check folder size function may get attacked by unsafe folder name
Aug 11, 2026
electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename
Aug 11, 2026
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
May 28, 2026
electerm: Local code through electerm's single-instance socket
May 28, 2026
electerm's encrypt method not safe enough
May 28, 2026
electerm: dangerous code can be run through links or command line
May 8, 2026
electerm: Full process.env exposed to renderer via window.pre.env in electerm
May 8, 2026
Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
May 8, 2026
electerm: Path traversal in electerm runWidget leads to arbitrary code execution
May 8, 2026
electerm: RCE via malicious SSH server filename in openFileWithEditor
May 8, 2026
electerm has Command Injection Vulnerability via runMac function
May 8, 2026
electerm has Command Injection Vulnerability via runLinux function
May 8, 2026
An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electe…
Jan 20, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-86711 | electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge | HIGH | 0.21% | Sep 8, 2026 |
| CVE-2026-49253 | electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling | HIGH | 0.44% | Aug 19, 2026 |
| CVE-2026-49255 | electerm: Command Injection in File System Operations (rmrf, mv, cp) | HIGH | 0.79% | Aug 19, 2026 |
| CVE-2026-73227 | electerm's RDP clipboard file download may parse unsafe file name | HIGH | 0.49% | Aug 11, 2026 |
| CVE-2026-73226 | Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist | HIGH | 0.75% | Aug 11, 2026 |
| CVE-2026-73225 | electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename | HIGH | 0.49% | Aug 11, 2026 |
| CVE-2026-73224 | Electerm check folder size function may get attacked by unsafe folder name | HIGH | 0.67% | Aug 11, 2026 |
| CVE-2026-73223 | electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename | HIGH | 0.49% | Aug 11, 2026 |
| CVE-2026-45058 | electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark | CRITICAL | 0.30% | May 28, 2026 |
| CVE-2026-45353 | electerm: Local code through electerm's single-instance socket | CRITICAL | 0.17% | May 28, 2026 |
| CVE-2026-45787 | electerm's encrypt method not safe enough | MEDIUM | 0.15% | May 28, 2026 |
| CVE-2026-43944 | electerm: dangerous code can be run through links or command line | CRITICAL | 0.65% | May 8, 2026 |
| CVE-2026-43942 | electerm: Full process.env exposed to renderer via window.pre.env in electerm | MEDIUM | 0.11% | May 8, 2026 |
| CVE-2026-43941 | Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click | CRITICAL | 0.51% | May 8, 2026 |
| CVE-2026-43940 | electerm: Path traversal in electerm runWidget leads to arbitrary code execution | CRITICAL | 0.22% | May 8, 2026 |
| CVE-2026-43943 | electerm: RCE via malicious SSH server filename in openFileWithEditor | HIGH | 0.24% | May 8, 2026 |
| CVE-2026-41500 | electerm has Command Injection Vulnerability via runMac function | CRITICAL | 2.49% | May 8, 2026 |
| CVE-2026-41501 | electerm has Command Injection Vulnerability via runLinux function | CRITICAL | 2.49% | May 8, 2026 |
| CVE-2020-23256 | An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electerms service. | CRITICAL | 0.86% | Jan 20, 2023 |
Showing 1 to 19 of 19 CVEs