electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mpm8-cx2p-626q | Electerm users can run dangrous code through link or command line |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 08 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Electerm Project
Electerm Project electerm |
|
| CPEs | cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Electerm Project
Electerm Project electerm |
|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15. | |
| Title | electerm: dangerous code can be run through links or command line | |
| Weaknesses | CWE-20 CWE-829 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T03:08:09.046Z
Reserved: 2026-05-04T16:59:09.090Z
Link: CVE-2026-43944
No data.
Status : Analyzed
Published: 2026-05-08T04:16:24.033
Modified: 2026-05-08T19:16:22.667
Link: CVE-2026-43944
No data.
OpenCVE Enrichment
Updated: 2026-05-08T05:30:46Z
Github GHSA