{"apiVersion":"1.0","identifier":"CVE-2026-49253","description":"electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/zmodem.js, prepareReceiveFile() joins the filename to the user-selected save path, and in src/app/server/trzsz.js, getUniqueFilePath(), the openSaveFile() callback, and the savedFilePaths mapping construct destinations without sanitization. A malicious SSH server or remote shell can provide a filename containing traversal components such as ../escaped.txt or ../../.bashrc. When the victim accepts the transfer and selects a download directory, electerm can write outside that directory and overwrite files accessible to the desktop user, potentially changing sensitive configuration or impairing availability. This issue is fixed in version 3.11.11.","publishedAt":"2026-08-19T15:17:06","lastModifiedAt":"2026-08-21T20:16:35","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49253","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","epssProbability":0.00336,"riskScore":0.73,"affectedProduct":"electerm","affectedVersions":"<3.11.11","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-49253","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-49253","en":"https://www.redsauce.net/en/cves/CVE-2026-49253","fr":"https://www.redsauce.net/fr/cves/CVE-2026-49253","pt":"https://www.redsauce.net/pt/cves/CVE-2026-49253","de":"https://www.redsauce.net/de/cves/CVE-2026-49253","sk":"https://www.redsauce.net/sk/cves/CVE-2026-49253","el":"https://www.redsauce.net/el/cves/CVE-2026-49253"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-49253"}}