Path Traversal Vulnerability in Electerm SSH Client
CVE-2026-43940
8.4HIGH
What is CVE-2026-43940?
The Electerm terminal client, prior to version 3.7.16, contains a path traversal vulnerability in its runWidget function, which allows an attacker to manipulate file paths through unsanitized user input. When a user-provided widget identifier is concatenated to create a file path without proper validation, an adversary can exploit this flaw if they can execute JavaScript within the renderer process. This could happen via a compromised plugin or a cross-site scripting bug within the webview, allowing the attacker to load and execute arbitrary JavaScript files from the victim's filesystem, leading to potential system compromise.
Affected Version(s)
electerm < 3.7.16
