electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim's machine, requiring only that the victim clicks a displayed link. At time of publication, there are no publicly available patches.
References
| Link | Resource |
|---|---|
| https://github.com/electerm/electerm/security/advisories/GHSA-fwf6-j56g-m97c | Vendor Advisory Mitigation |
Configurations
History
08 May 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/electerm/electerm/security/advisories/GHSA-fwf6-j56g-m97c - Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:* | |
| First Time |
Electerm Project
Electerm Project electerm |
08 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 04:16
Updated : 2026-05-08 19:17
NVD link : CVE-2026-43941
Mitre link : CVE-2026-43941
CVE.ORG link : CVE-2026-43941
JSON object : View
Products Affected
electerm_project
- electerm
