Electerm是中国zxdong262个人开发者的一款基于 electron 开发的 SSH/SFTP 客户端。 electerm 3.0.6至3.8.15之前版本存在输入验证错误漏洞,该漏洞源于通过深度链接、CLI --opts或特制快捷方式可能导致任意本地代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41501 | 9.8 CRITICAL | electerm has Command Injection Vulnerability via runLinux function |
| CVE-2026-41500 | 9.8 CRITICAL | electerm has Command Injection Vulnerability via runMac function |
| CVE-2026-43941 | 9.6 CRITICAL | Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via termina |
| CVE-2026-43940 | 8.4 HIGH | electerm: Path traversal in electerm runWidget leads to arbitrary code execution |
| CVE-2026-43943 | 7.8 HIGH | electerm: RCE via malicious SSH server filename in openFileWithEditor |
| CVE-2026-43942 | 5.5 MEDIUM | electerm: Full process.env exposed to renderer via window.pre.env in electerm |
No comments yet