Command Injection Vulnerability in Electerm by Electerm
CVE-2026-41501
9.8CRITICAL
What is CVE-2026-41501?
Electerm, an open-source terminal and client application, is vulnerable to command injection due to improper handling of version strings in the runLinux() function. Unvalidated input from attacker-controlled remote versions can lead to the execution of malicious commands, such as the destructive 'rm -rf' command. This vulnerability has been addressed in release 3.3.8, protecting users from potential exploits.
Affected Version(s)
electerm < 3.3.8
