Vulnerabilidades em electerm

18 resultados
Análise Vexday

Electerm apresenta 10 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 6 delas em nível crítico, indicando descobertas recentes e concentradas. A fraqueza dominante é CWE-94 (execução de código não confiável), representando risco elevado de comprometimento, embora nenhuma esteja sob exploração ativa conhecida no momento. A recência e concentração de críticas demandam revisão urgente de patches e isolamento de instâncias afetadas em ambientes sensíveis.

CVE-2026-41501CRITICALelecterm has Command Injection Vulnerability via runLinux functionEPSS 2.5%CVE-2026-41500CRITICALelecterm has Command Injection Vulnerability via runMac functionEPSS 2.5%CVE-2026-49255HIGHelecterm: Command Injection in File System Operations (rmrf, mv, cp)EPSS 0.8%CVE-2026-73226HIGHElecterm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlistEPSS 0.8%CVE-2026-73224HIGHElecterm check folder size function may get attacked by unsafe folder nameEPSS 0.7%CVE-2026-43944CRITICALelecterm: dangerous code can be run through links or command lineEPSS 0.6%CVE-2026-43941CRITICALUnvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link clickEPSS 0.5%CVE-2026-73227HIGHelecterm's RDP clipboard file download may parse unsafe file nameEPSS 0.5%CVE-2026-73225HIGHelecterm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filenameEPSS 0.5%CVE-2026-73223HIGHelecterm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filenameEPSS 0.5%CVE-2026-49253HIGHelecterm: Path Traversal in Zmodem and Trzsz Download Filename HandlingEPSS 0.4%CVE-2026-45058CRITICALelecterm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmarkEPSS 0.3%CVE-2026-43943HIGHelecterm: RCE via malicious SSH server filename in openFileWithEditorEPSS 0.2%CVE-2026-43940HIGHelecterm: Path traversal in electerm runWidget leads to arbitrary code executionEPSS 0.2%CVE-2026-86711HIGHelecterm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC BridgeEPSS 0.2%CVE-2026-45353CRITICALelecterm: Local code through electerm's single-instance socketEPSS 0.2%CVE-2026-45787MEDIUMelecterm's encrypt method not safe enoughEPSS 0.1%CVE-2026-43942MEDIUMelecterm: Full process.env exposed to renderer via window.pre.env in electermEPSS 0.1%