Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-86711
  • github.com/electerm/electerm
electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge 08 Sep
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-49253
  • github.com/electerm/electerm
electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling 19 Aug
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-49255
  • github.com/electerm/electerm
electerm: Command Injection in File System Operations (rmrf, mv, cp) 19 Aug
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-73227
  • github.com/electerm/electerm
electerm's RDP clipboard file download may parse unsafe file name 11 Aug
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-73226
  • github.com/electerm/electerm
Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist 11 Aug
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-73225
  • github.com/electerm/electerm
electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename 11 Aug
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-73224
  • github.com/electerm/electerm
Electerm check folder size function may get attacked by unsafe folder name 11 Aug
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-73223
  • github.com/electerm/electerm
electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename 11 Aug
  • Fix available
  • Severity - 8.1 (High)
GHSA-v5ff-xmfp-p245
  • npm/electerm
electerm has Command Injection in File System Operations (rmrf, mv, cp) 02 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-38j7-23hf-9mhc
  • npm/electerm
electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling 02 Jul
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-45058
  • github.com/electerm/electerm
electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark 28 May
  • No fix available
  • Severity - 9.4 (Critical)
CVE-2026-45353
  • github.com/electerm/electerm
electerm: Local code through electerm's single-instance socket 28 May
  • Fix available
  • Severity - 9.3 (Critical)
CVE-2026-45787
  • github.com/electerm/electerm
electerm's encrypt method not safe enough 28 May
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-g29v-q6h7-76wh
  • npm/electerm
electerm's encrypt method not safe enough 14 May
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-7p5m-v798-f8vv
  • npm/electerm
Electerm Local code through electerm's single-instance socket 14 May
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-jgg9-rw32-44pj
  • npm/electerm
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark 14 May
  • No fix available
  • Severity - 9.4 (Critical)