Technology · npm
electerm (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in electerm (npm): 0 in the last 7 days and 8 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86711, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 5
- Exploited in the wild
- 0
About electerm (npm)
A terminal emulator, SSH, and SFTP client for desktop operating systems.
Latest electerm (npm) vulnerabilities
- CVE-2026-86711: electerm IPC handler privilege escalation in main processhighCVSS 7.4EPSS 0.2%
- CVE-2026-73227: electerm unsafe RDP filename in clipboard downloadhighCVSS 8.1EPSS 0.5%
- CVE-2026-73226: electerm authenticated method invocation vulnerabilityhighCVSS 8.8EPSS 0.8%
- CVE-2026-73225: electerm path traversal in FTP/SFTP file transferhighCVSS 8.1EPSS 0.5%
- CVE-2026-73224: electerm shell injection in folder size calculationhighCVSS 8.8EPSS 0.7%
- CVE-2026-73223: electerm path traversal via unsanitized SFTP filenamehighCVSS 8.1EPSS 0.5%
- CVE-2026-49255: electerm OS command injection in file system operationshighCVSS 8.8EPSS 0.8%
- CVE-2026-49253: electerm path traversal in Zmodem and Trzsz download handlershighCVSS 7.1EPSS 0.4%
- CVE-2026-45787: electerm weak encryption in synced profile datamediumCVSS 4EPSS 0.1%
- CVE-2026-45353: electerm local code execution via single-instance sockethighCVSS 7.8EPSS 0.2%
- CVE-2026-45058: electerm code execution via imported bookmarks or sync targetscriticalCVSS 4EPSS 0.3%
- CVE-2026-43943: Electerm command injection in openFileWithEditor via malicious SSH filenamelowCVSS 3.1EPSS 0.2%
- CVE-2026-43942: Electerm sensitive information exposure in renderer via window.pre.envlowCVSS 3.1EPSS 0.1%
- CVE-2026-43941: Electerm unvalidated shell.openExternal arbitrary protocol executionlowCVSS 3.1EPSS 0.5%
- CVE-2026-43940: Electerm runWidget path traversal leading to code executionlowCVSS 3.1EPSS 0.2%
- CVE-2026-43944: electerm code execution via deep links or CLI optionscriticalCVSS 9.6EPSS 0.7%
- CVE-2026-41501: electerm command injection in runLinux functioncriticalCVSS 9.8EPSS 2.5%
- CVE-2026-41500: electerm: electerm_install_script_CommandInjection Vulnerability ReportcriticalCVSS 9.8EPSS 2.5%
- CVE-2020-23256: Electerm OS command injection via unverified service requestcriticalCVSS 9.8EPSS 0.9%
Most severe electerm (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-41501: electerm command injection in runLinux functioncriticalCVSS 9.8EPSS 2.5%
- CVE-2026-41500: electerm: electerm_install_script_CommandInjection Vulnerability ReportcriticalCVSS 9.8EPSS 2.5%
- CVE-2020-23256: Electerm OS command injection via unverified service requestcriticalCVSS 9.8EPSS 0.9%
- CVE-2026-43944: electerm code execution via deep links or CLI optionscriticalCVSS 9.6EPSS 0.7%
- CVE-2026-45058: electerm code execution via imported bookmarks or sync targetscriticalCVSS 4EPSS 0.3%
- CVE-2026-49255: electerm OS command injection in file system operationshighCVSS 8.8EPSS 0.8%
- CVE-2026-73226: electerm authenticated method invocation vulnerabilityhighCVSS 8.8EPSS 0.8%
- CVE-2026-73224: electerm shell injection in folder size calculationhighCVSS 8.8EPSS 0.7%
- CVE-2026-73227: electerm unsafe RDP filename in clipboard downloadhighCVSS 8.1EPSS 0.5%
- CVE-2026-73225: electerm path traversal in FTP/SFTP file transferhighCVSS 8.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 5 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/electerm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "electerm (npm) vulnerabilities", https://junglewise.ai/threats/technologies/electerm, 28 September 2026.