CVE-2026-45353

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:*

History

03 Jun 2026, 17:54

Type Values Removed Values Added
First Time Electerm Project
Electerm Project electerm
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://github.com/electerm/electerm/commit/0599e67069b00e376a2e962649aaad6096e63507 - () https://github.com/electerm/electerm/commit/0599e67069b00e376a2e962649aaad6096e63507 - Patch
References () https://github.com/electerm/electerm/security/advisories/GHSA-7p5m-v798-f8vv - () https://github.com/electerm/electerm/security/advisories/GHSA-7p5m-v798-f8vv - Vendor Advisory, Patch
CPE cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:*

28 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 18:16

Updated : 2026-06-03 17:54


NVD link : CVE-2026-45353

Mitre link : CVE-2026-45353

CVE.ORG link : CVE-2026-45353


JSON object : View

Products Affected

electerm_project

  • electerm
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-940

Improper Verification of Source of a Communication Channel