Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
Not yet
{
"cwe_ids": [
"CWE-345",
"CWE-494",
"CWE-915",
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-14T20:15:42Z",
"nvd_published_at": "2026-05-28T18:16:34Z",
"severity": "CRITICAL"
}