Impact
Electerm versions prior to 5.3.15 expose more than forty main‑process functions through an Electron IPC handler that accepts messages from renderer pages without validating the function name or the sender. The handler allows renderer scripts to invoke functions such as openFileWithEditor with any arguments, enabling execution of arbitrary system commands by the main process. The flaw therefore results in arbitrary command execution and a complete compromise of the host machine if an attacker can influence the renderer environment.
Affected Systems
All electerm installations running a version older than 5.3.15 are vulnerable. The affected product is electerm and the vulnerability affects all builds before the 5.3.15 release. No specific patch version is listed beyond 5.3.15, so any earlier release remains at risk.
Risk and Exploitability
The vulnerability scores a CVSS 7.5, indicating a high severity. EPSS data is not available, so the likelihood of exploitation is uncertain but the impact is significant. The flaw is listed as not on the CISA KEV catalog. Exploitation would require an attacker to deliver a payload that runs in the renderer process, for example by tricking a user into loading a malicious script or file. Once attained, the attacker can execute system commands with the privileges of the Electerm main process.
OpenCVE Enrichment