{"apiVersion":"1.0","identifier":"CVE-2026-49255","description":"electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), and cp() functions. A malicious SSH or SFTP server can provide a filename containing quote characters and shell metacharacters, and a victim can cause that filename to reach the affected operation during remote-to-local transfer, conflict renaming, copying, moving, or removal. The generated `rm -rf`, mv, `cp -r`, PowerShell Remove-Item, Move-Item, or Copy-Item command can then interpret the filename as shell syntax. This allows arbitrary command execution with the electerm desktop user-s privileges on POSIX and Windows systems, enabling data exfiltration, file modification, malware installation, or denial of service. This issue is fixed in version 3.11.11.","publishedAt":"2026-08-19T15:17:06","lastModifiedAt":"2026-08-25T03:16:55","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49255","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","epssProbability":0.00527,"riskScore":0.92,"affectedProduct":"electerm","affectedVersions":"<3.11.11","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-49255","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-49255","en":"https://www.redsauce.net/en/cves/CVE-2026-49255","fr":"https://www.redsauce.net/fr/cves/CVE-2026-49255","pt":"https://www.redsauce.net/pt/cves/CVE-2026-49255","de":"https://www.redsauce.net/de/cves/CVE-2026-49255","sk":"https://www.redsauce.net/sk/cves/CVE-2026-49255","el":"https://www.redsauce.net/el/cves/CVE-2026-49255"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-49255"}}