Junglewise Threat Intelligence

CVE-2026-43942: Electerm sensitive information exposure in renderer via window.pre.env

CVE-2026-43942 · Severity: low · CVSS 3.1 · Published 2026-05-08

Technologies: electerm (npm). Vendors: npm.

Executive brief

Electerm, a cross-platform terminal and SSH client, exposes the full set of environment variables (including API keys, AWS credentials, and GitHub tokens) to its renderer process where they are accessible to any JavaScript code. An attacker with JavaScript execution capability in the renderer—such as through a malicious plugin, cross-site scripting vulnerability, or terminal hyperlink execution—can steal these secrets and compromise cloud accounts or perform supply chain attacks.

Technical details

The vulnerability exists in the getConstants() IPC handler in src/app/lib/ipc-sync.js, which serializes the entire process.env object and sends it to the renderer process, where it is stored as window.pre.env. This object is accessible to any JavaScript code executing within the renderer context, including browser DevTools, malicious plugins, or code injected via XSS or terminal hyperlink execution chains. On developer and CI machines, process.env typically contains sensitive secrets such as AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, OPENAI_API_KEY, and database credentials. An attacker achieving JavaScript execution in the renderer can exfiltrate these credentials to a remote server, leading to cloud account compromise, supply chain attacks, and lateral movement. The advisory notes that the exposure is visible even without code execution by opening the Info modal, though local access is required. No patch has been released as of the advisory publication date.

Affected products

  • electerm electerm all versions up to and including 3.8.15

Timeline

  • 2026-05-08: disclosed
  • 2026-05-08: other: advisory published; patch not yet available

References

Related threats