Descripción
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm-s terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim-s machine, requiring only that the victim clicks a displayed link. At time of publication, there are no publicly available patches.
CVSS 9.6EPSS 0.394%Riesgo 0.99
Ver fuente- Publicación
- 2026-05-08 04:16:23
- Versiones afectadas
- <=3.8.15
- Tipo
- Software crítico
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H