electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
An attacker injects exec* fields or malicious global configuration into a JSON bookmarks file or synchronization target (e.g., GitHub Gist or WebDAV server). When the user opens an infected bookmark or applies synchronization, electerm executes the injected code without proper integrity verification or data source validation. This mechanism corresponds to CWE-94 (code injection), CWE-345/CWE-494 (lack of verification of downloaded code integrity), and CWE-915 (uncontrolled modification of object properties). The malicious code is executed in the context of a local pseudo-terminal (pty), providing the attacker with persistent access.
An attacker can gain full control over the victim's system by executing arbitrary code locally — both in user context and potentially in system context. Consequences include data theft, malware installation, and the ability to perform lateral movement within the network.
Apply patches available from the vendor according to references (https://github.com/electerm/electerm/security/advisories/GHSA-jgg9-rw32-44pj). Until updating, it is recommended to stop importing bookmarks from untrusted sources and disable synchronization features (gist/WebDAV).
electerm version 3.8.8 and earlier — affects users importing JSON bookmarks files or using electerm synchronization features (GitHub Gist or WebDAV)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X