CRITICAL🇵🇱 Wersja polska

CVE-2026-43944

CVSS 9.4v4.0pub. 2026-05-08upd. 2026-05-13

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.

🤖 AI Analysis
How it works

The vulnerability results from insufficient input validation (CWE-20) combined with the possibility of code injection and execution (CWE-94) and loading resources from untrusted locations (CWE-829). The attack involves tricking a user into clicking a crafted link in the electerm://... scheme, opening a crafted system shortcut, or running electerm with CLI parameters controlled by the attacker. The application processes the passed options (opts) without proper sanitization, leading to arbitrary code execution locally on the victim's machine.

Impact

An attacker can execute arbitrary code in the context of the user running the application, which may result in full system compromise, data theft (including SSH keys, passwords, connection configurations), and further lateral movement in the network.

Mitigation & patch

Update electerm to version 3.8.15 or later, in which the vulnerability has been fixed. Patches are available in the vendor references (GitHub Releases: v3.8.15).

Who is affected

electerm (Electerm Project) in versions from 3.0.6 to 3.8.14 inclusive (before 3.8.15)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Electerm Project Electerm

    APP
    Electerm Project
    3.0.6 – 3.8.15 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-45353CRITICAL9.3PL ✓same product

Krytyczna podatność w kliencie electerm (wersje 3.0.6–3.8.8)

CVE-2026-43941CRITICAL9.6PL ✓same product

RCE w Electerm — brak walidacji protokołu URL w handlerze hiperłączy

CVE-2026-41500CRITICAL9.8PL ✓same product

Command injection w electerm — wykonanie kodu przez złośliwe releaseInfo.name

CVE-2026-41501CRITICAL9.8PL ✓same product

Command injection w Electerm — wstrzyknięcie polecenia przez zdalny ciąg wersji

CVE-2020-23256CRITICAL9.8PL ✓same product

Wykonanie dowolnego kodu w Electerm przez niezweryfikowane żądanie do usługi