electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim's machine, requiring only that the victim clicks a displayed link. At time of publication, there are no publicly available patches.
An attacker controlling data displayed in the terminal (for example through a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can embed a specially crafted hyperlink in the terminal output. When the victim clicks on this link, Electerm passes the URL — without any protocol validation — to the system's shell.openExternal call. Due to the lack of filtering, the URL can contain schemes other than http/https (for example file://, custom protocol handlers), leading to arbitrary code execution or reading of local files. The vulnerability requires only a single user click on the displayed link (CWE-88: improper neutralization of arguments, CWE-601: open redirect / improper URL handling).
An attacker can achieve remote code execution (RCE) on the victim's machine or gain unauthorized access to local system files, which combined with high impact scope (Scope: Changed) can lead to full system compromise.
At the time of vulnerability publication, no public patches were available. You should monitor the official project repository (https://github.com/electerm/electerm) and the GHSA-fwf6-j56g-m97c security advisory and apply the patch immediately upon release. Until a fix is released, it is recommended to avoid clicking any links displayed in the Electerm terminal window, especially when connected to untrusted SSH hosts, and to limit the use of the application to trusted environments.
Electerm in versions 3.8.15 and earlier (Electerm Project Electerm project).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HElecterm Project Electerm
APPElecterm Project≤ 3.8.15
Related vulnerabilities
Krytyczna podatność w kliencie electerm (wersje 3.0.6–3.8.8)
Command injection w electerm — wykonanie kodu przez złośliwe releaseInfo.name
RCE w electerm — wykonanie kodu przez deep links i spreparowane skróty
Command injection w Electerm — wstrzyknięcie polecenia przez zdalny ciąg wersji
Wykonanie dowolnego kodu w Electerm przez niezweryfikowane żądanie do usługi