GHSA-38j7-23hf-9mhc

Suggest an improvement
Source
https://github.com/advisories/GHSA-38j7-23hf-9mhc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-38j7-23hf-9mhc/GHSA-38j7-23hf-9mhc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-38j7-23hf-9mhc
Aliases
Published
2026-07-02T19:20:20Z
Modified
2026-07-02T19:41:33Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L CVSS Calculator
Summary
electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling
Details

Impact

A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.

A malicious SSH server or remote shell process can send a specially crafted filename such as ../escaped.txt to escape the user-selected download directory and write files to arbitrary locations on the user's filesystem, subject to process permissions.

Attack scenario:

  1. User connects to a malicious SSH server
  2. Attacker initiates a Zmodem or Trzsz file transfer
  3. Attacker supplies a traversal filename (e.g., ../../.bashrc, ../escaped.txt)
  4. User accepts the transfer and selects a download directory
  5. File is written outside the selected directory, potentially overwriting sensitive files

Affected components:

  • src/app/server/zmodem.js - prepareReceiveFile() at line 736
  • src/app/server/trzsz.js - getUniqueFilePath() at line 559, openSaveFile() callback, and savedFilePaths mapping

Patches

Workarounds

If upgrading is not immediately possible, users can mitigate this vulnerability by:

  1. Only connecting to trusted SSH servers
  2. Rejecting or canceling any incoming Zmodem or Trzsz file transfers from untrusted sources
  3. Avoiding the use of Zmodem (sz/rz) and Trzsz (trz/tsz) commands on untrusted servers
Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T19:20:20Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / electerm

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.11

Database specific

last_known_affected_version_range
"<= 3.11.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-38j7-23hf-9mhc/GHSA-38j7-23hf-9mhc.json"