Path Traversal Vulnerability in Electerm SSH Client
CVE-2026-43940

8.4HIGH

Key Information:

Vendor

Electerm

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-43940?

The Electerm terminal client, prior to version 3.7.16, contains a path traversal vulnerability in its runWidget function, which allows an attacker to manipulate file paths through unsanitized user input. When a user-provided widget identifier is concatenated to create a file path without proper validation, an adversary can exploit this flaw if they can execute JavaScript within the renderer process. This could happen via a compromised plugin or a cross-site scripting bug within the webview, allowing the attacker to load and execute arbitrary JavaScript files from the victim's filesystem, leading to potential system compromise.

Affected Version(s)

electerm < 3.7.16

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.