Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
Published: 2026-05-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Electerm, an open‑source terminal and remote‑access client, contains a flaw that allows an attacker to cause the client to execute arbitrary commands by injecting specially crafted fields into imported bookmark JSON files or into global configuration values that are applied when a sync target is refreshed. The flaw is identified as a persistent local‑pty code execution vulnerability. When a bookmark is opened or a sync operation is applied, the injected exec* fields or modified global settings are processed and executed with the privileges of the user running Electerm, effectively granting the attacker remote code execution on the local machine.

Affected Systems

All Electerm product releases at or below version 3.8.8 are vulnerable. The issue manifests when users import bookmark files or enable Electerm sync (e.g., gist or WebDAV). The flaw exists across internal bookmark handling, regardless of the specific transport used to synchronize data.

Risk and Exploitability

This vulnerability receives a CVSS score of 9.4, indicating a critical impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply a malicious bookmark file or to compromise a sync target such as a gist or WebDAV server. Upon delivery, opening the bookmark or triggering a sync refresh will execute arbitrary code with the local user's privileges, thereby providing full control over the affected system. Social engineering or compromised remote sync repositories are the primary means of deployment.

Generated by OpenCVE AI on May 28, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Electerm to the latest available release, which removes the unsafe processing of bookmark imports and sync data.
  • If an upgrade cannot be performed immediately, disable the bookmark import feature and remove any existing imported bookmarks until a patched version is available.
  • Similarly, suspend or reconfigure any active sync targets (gist, WebDAV, etc.) to prevent remote injection of malicious configuration data.

Generated by OpenCVE AI on May 28, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jgg9-rw32-44pj Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
History

Thu, 28 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Electerm
Electerm electerm
Vendors & Products Electerm
Electerm electerm

Thu, 28 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
Title electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
Weaknesses CWE-345
CWE-494
CWE-915
CWE-94
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Electerm Electerm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-28T17:20:41.799Z

Reserved: 2026-05-08T18:07:27.342Z

Link: CVE-2026-45058

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T18:16:34.313

Modified: 2026-05-28T18:16:34.313

Link: CVE-2026-45058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T19:30:16Z