CVE-2026-45058

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
CVSS

No CVSS.

Configurations

No configuration.

History

28 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 18:16

Updated : 2026-06-01 18:38


NVD link : CVE-2026-45058

Mitre link : CVE-2026-45058

CVE.ORG link : CVE-2026-45058


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-345

Insufficient Verification of Data Authenticity

CWE-494

Download of Code Without Integrity Check

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes