Electerm是中国zxdong262个人开发者的一款基于 electron 开发的 SSH/SFTP 客户端。 Electerm 3.8.15及之前版本存在参数注入漏洞,该漏洞源于终端超链接处理器未对URL进行协议验证,可能导致攻击者通过恶意SSH服务器或远程主机控制终端输出,实现任意代码执行或本地文件访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41501 | 9.8 CRITICAL | electerm has Command Injection Vulnerability via runLinux function |
| CVE-2026-41500 | 9.8 CRITICAL | electerm has Command Injection Vulnerability via runMac function |
| CVE-2026-43940 | 8.4 HIGH | electerm: Path traversal in electerm runWidget leads to arbitrary code execution |
| CVE-2026-43943 | 7.8 HIGH | electerm: RCE via malicious SSH server filename in openFileWithEditor |
| CVE-2026-43942 | 5.5 MEDIUM | electerm: Full process.env exposed to renderer via window.pre.env in electerm |
| CVE-2026-43944 | electerm: dangerous code can be run through links or command line |
No comments yet