Arbitrary Code Execution Vulnerability in Electerm Terminal Client by Electerm
CVE-2026-43944
9.4CRITICAL
What is CVE-2026-43944?
Electerm, an open-source terminal and SSH client, is susceptible to a vulnerability that permits arbitrary local code execution. This occurs through specially crafted deep links, command-line options, or shortcuts that can contain malicious parameters. The exploit requires user interaction, such as clicking a malicious electerm:// link or executing a malicious command that triggers Electerm with manipulated options. Users are encouraged to upgrade to version 3.8.15 or later to mitigate this risk.
Affected Version(s)
electerm >= 3.0.6, < 3.8.15
