Executive brief
electerm, a terminal and ssh/sftp client, is vulnerable to a command injection flaw. If a user connects to a malicious server, the server can send specially crafted filenames that trigger arbitrary command execution on the user's computer. This could lead to full system compromise, data theft, or malware installation.
Technical details
A command injection vulnerability exists in electerm's file system operations (rmrf, mv, cp) within src/app/lib/fs.js. The application constructs shell commands by interpolating file paths directly into command strings using double or single quotes without proper escaping of shell metacharacters. An attacker controlling a malicious SSH/SFTP server can provide filenames containing shell breakout sequences (e.g., $(command)). When a victim performs file operations like transfers or renames on these files, the injected commands are executed with the privileges of the electerm user. This affects both POSIX (bash) and Windows (PowerShell) platforms. The issue is patched in version 3.11.11.
Affected products
- electerm electerm <= 3.11.0
Timeline
- 2026-05-29: disclosed
- 2026-07-02: advisory: GHSA-v5ff-xmfp-p245 published
- 2026-07-02: patched