Executive brief
Electerm, a terminal and ssh/sftp client, is vulnerable to a security flaw that allows attackers to execute malicious code on a user's computer. This occurs when a user imports a specially crafted bookmark file or connects to a compromised synchronization service like GitHub Gist or WebDAV. If exploited, an attacker could gain full control over the user's local terminal environment, potentially leading to data theft or further system compromise.
Technical details
Electerm versions up to and including 3.8.8 are vulnerable to code injection (CWE-94) and improper verification of data authenticity (CWE-345). The vulnerability exists in the bookmark import and synchronization mechanisms (Gist/WebDAV), where an attacker can inject malicious 'exec*' fields or global configurations into bookmark JSON data. When a user interacts with a poisoned 'local' type bookmark or applies a malicious sync configuration, the injected commands are executed within the local pseudo-terminal (pty) context. This allows for persistent remote code execution on the host machine. As of the advisory date, no official patch is available, and users are advised to avoid importing data from untrusted sources.
Affected products
- electerm electerm <= 3.8.8
Timeline
- 2026-05-14: advisory: GitHub Advisory published
- 2026-05-28: disclosed: NVD publication date
References
- https://api.github.com/users/Curly-Haired-Baboon
- https://github.com/Curly-Haired-Baboon
- https://api.github.com/users/Curly-Haired-Baboon/gists%7B/gist_id%7D
- https://api.github.com/users/Curly-Haired-Baboon/repos
- https://avatars.githubusercontent.com/u/227850795?v=4
- https://api.github.com/users/Curly-Haired-Baboon/events%7B/privacy%7D