electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.
Metrics
Affected Vendors & Products
References
History
Fri, 08 May 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15. | |
| Title | electerm: dangerous code can be run through links or command line | |
| Weaknesses | CWE-20 CWE-829 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T03:08:09.046Z
Reserved: 2026-05-04T16:59:09.090Z
Link: CVE-2026-43944
No data.
Status : Received
Published: 2026-05-08T04:16:24.033
Modified: 2026-05-08T04:16:24.033
Link: CVE-2026-43944
No data.
OpenCVE Enrichment
Updated: 2026-05-08T05:30:46Z