← Volver al buscador de CVEs

CVE-2026-43943

electerm

Descripción

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerability exists in electerm-s SFTP open with system editor or -Edit with custom editor- feature. When a user opts to edit a file using open with system editor or open with a custom editor, the filename is passed directly into a command line without sanitization. A malicious actor controlling the SSH server or user OS can exploit this by crafting a filename containing shell metacharacters. If a victim subsequently attempts to edit this file, the injected commands are executed on their machine with the user-s privileges. This could allow the attacker to run arbitrary code, install malware, or move laterally within the network. This issue has been patched in version 3.7.9.

CVSS 7.8EPSS 0.165%Riesgo 0.79
Ver fuente
Publicación
2026-05-08 04:16:23
Versiones afectadas
<3.7.9
Tipo
Software crítico
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H