Electerm

Electerm · 19 CVEs

CVE-2026-86711
HIGH

electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge

Sep 8, 2026

CVE-2026-49253
HIGH

electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling

Aug 19, 2026

CVE-2026-49255
HIGH

electerm: Command Injection in File System Operations (rmrf, mv, cp)

Aug 19, 2026

CVE-2026-73227
HIGH

electerm's RDP clipboard file download may parse unsafe file name

Aug 11, 2026

CVE-2026-73226
HIGH

Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-na…

Aug 11, 2026

CVE-2026-73225
HIGH

electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename

Aug 11, 2026

CVE-2026-73224
HIGH

Electerm check folder size function may get attacked by unsafe folder name

Aug 11, 2026

CVE-2026-73223
HIGH

electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename

Aug 11, 2026

CVE-2026-45058
CRITICAL

electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark

May 28, 2026

CVE-2026-45353
CRITICAL

electerm: Local code through electerm's single-instance socket

May 28, 2026

CVE-2026-45787
MEDIUM

electerm's encrypt method not safe enough

May 28, 2026

CVE-2026-43944
CRITICAL

electerm: dangerous code can be run through links or command line

May 8, 2026

CVE-2026-43942
MEDIUM

electerm: Full process.env exposed to renderer via window.pre.env in electerm

May 8, 2026

CVE-2026-43941
CRITICAL

Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click

May 8, 2026

CVE-2026-43940
CRITICAL

electerm: Path traversal in electerm runWidget leads to arbitrary code execution

May 8, 2026

CVE-2026-43943
HIGH

electerm: RCE via malicious SSH server filename in openFileWithEditor

May 8, 2026

CVE-2026-41500
CRITICAL

electerm has Command Injection Vulnerability via runMac function

May 8, 2026

CVE-2026-41501
CRITICAL

electerm has Command Injection Vulnerability via runLinux function

May 8, 2026

CVE-2020-23256
CRITICAL

An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electe…

Jan 20, 2023

Showing 1 to 19 of 19 CVEs