electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.

Project Subscriptions

Vendors Products
Electerm Subscribe
Electerm Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jgg9-rw32-44pj Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 28 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Electerm
Electerm electerm
Vendors & Products Electerm
Electerm electerm

Thu, 28 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
Title electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
Weaknesses CWE-345
CWE-494
CWE-915
CWE-94
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-28T17:20:41.799Z

Reserved: 2026-05-08T18:07:27.342Z

Link: CVE-2026-45058

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T18:16:34.313

Modified: 2026-05-28T18:16:34.313

Link: CVE-2026-45058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T19:30:16Z