๐Ÿ” CVE Alert

CVE-2026-45058

UNKNOWN 0.0

electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.

CWE CWE-94 CWE-345 CWE-494 CWE-915
Vendor electerm
Product electerm
Published May 28, 2026
Last Updated May 30, 2026
Stay Ahead of the Next One

Get instant alerts for electerm electerm

Be the first to know when new unknown vulnerabilities affecting electerm electerm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

electerm / electerm
<= 3.8.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/electerm/electerm/security/advisories/GHSA-jgg9-rw32-44pj