Electerm
This hub aggregates every CVE we track for Electerm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
6
Critical
10
High
0
In CISA KEV
Severity distribution
HIGH10CRITICAL6MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
9
0
0
7
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Electerm.
- CVE-2026-49253electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling7.1
- CVE-2026-49255electerm: Command Injection in File System Operations (rmrf, mv, cp)8.8
- CVE-2026-73227electerm's RDP clipboard file download may parse unsafe file name8.1
- CVE-2026-73226Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist8.8
- CVE-2026-73225electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename8.1
- CVE-2026-73224Electerm check folder size function may get attacked by unsafe folder name8.8
- CVE-2026-73223electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename8.1
- CVE-2026-45353electerm: Local code through electerm's single-instance socket7.8
- CVE-2026-45787electerm's encrypt method not safe enough9.1
- CVE-2026-43944electerm: dangerous code can be run through links or command line9.6
- CVE-2026-43942electerm: Full process.env exposed to renderer via window.pre.env in electerm5.5
- CVE-2026-43941Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click9.6
- CVE-2026-43940electerm: Path traversal in electerm runWidget leads to arbitrary code execution8.4
- CVE-2026-43943electerm: RCE via malicious SSH server filename in openFileWithEditor7.8
- CVE-2026-41500electerm has Command Injection Vulnerability via runMac function9.8
Product normalization is registry-driven with AI assist and human review. How it works