CRITICAL🇵🇱 Wersja polska

CVE-2026-43941

CVSS 9.6v3.1pub. 2026-05-08

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim's machine, requiring only that the victim clicks a displayed link. At time of publication, there are no publicly available patches.

🤖 AI Analysis
How it works

An attacker controlling data displayed in the terminal (for example through a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can embed a specially crafted hyperlink in the terminal output. When the victim clicks on this link, Electerm passes the URL — without any protocol validation — to the system's shell.openExternal call. Due to the lack of filtering, the URL can contain schemes other than http/https (for example file://, custom protocol handlers), leading to arbitrary code execution or reading of local files. The vulnerability requires only a single user click on the displayed link (CWE-88: improper neutralization of arguments, CWE-601: open redirect / improper URL handling).

Impact

An attacker can achieve remote code execution (RCE) on the victim's machine or gain unauthorized access to local system files, which combined with high impact scope (Scope: Changed) can lead to full system compromise.

Mitigation & patch

At the time of vulnerability publication, no public patches were available. You should monitor the official project repository (https://github.com/electerm/electerm) and the GHSA-fwf6-j56g-m97c security advisory and apply the patch immediately upon release. Until a fix is released, it is recommended to avoid clicking any links displayed in the Electerm terminal window, especially when connected to untrusted SSH hosts, and to limit the use of the application to trusted environments.

Who is affected

Electerm in versions 3.8.15 and earlier (Electerm Project Electerm project).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Electerm Project Electerm

    APP
    Electerm Project
    ≤ 3.8.15
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-45353CRITICAL9.3PL ✓same product

Krytyczna podatność w kliencie electerm (wersje 3.0.6–3.8.8)

CVE-2026-41500CRITICAL9.8PL ✓same product

Command injection w electerm — wykonanie kodu przez złośliwe releaseInfo.name

CVE-2026-43944CRITICAL9.4PL ✓same product

RCE w electerm — wykonanie kodu przez deep links i spreparowane skróty

CVE-2026-41501CRITICAL9.8PL ✓same product

Command injection w Electerm — wstrzyknięcie polecenia przez zdalny ciąg wersji

CVE-2020-23256CRITICAL9.8PL ✓same product

Wykonanie dowolnego kodu w Electerm przez niezweryfikowane żądanie do usługi