electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.
The vulnerability results from insufficient input validation (CWE-20) combined with the possibility of code injection and execution (CWE-94) and loading resources from untrusted locations (CWE-829). The attack involves tricking a user into clicking a crafted link in the electerm://... scheme, opening a crafted system shortcut, or running electerm with CLI parameters controlled by the attacker. The application processes the passed options (opts) without proper sanitization, leading to arbitrary code execution locally on the victim's machine.
An attacker can execute arbitrary code in the context of the user running the application, which may result in full system compromise, data theft (including SSH keys, passwords, connection configurations), and further lateral movement in the network.
Update electerm to version 3.8.15 or later, in which the vulnerability has been fixed. Patches are available in the vendor references (GitHub Releases: v3.8.15).
electerm (Electerm Project) in versions from 3.0.6 to 3.8.14 inclusive (before 3.8.15)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XElecterm Project Electerm
APPElecterm Project3.0.6 – 3.8.15 (excl.)
Related vulnerabilities
Krytyczna podatność w kliencie electerm (wersje 3.0.6–3.8.8)
RCE w Electerm — brak walidacji protokołu URL w handlerze hiperłączy
Command injection w electerm — wykonanie kodu przez złośliwe releaseInfo.name
Command injection w Electerm — wstrzyknięcie polecenia przez zdalny ciąg wersji
Wykonanie dowolnego kodu w Electerm przez niezweryfikowane żądanie do usługi