Local Code Execution Vulnerability in Electerm Client by Electerm
CVE-2026-45058
9.4CRITICAL
What is CVE-2026-45058?
The Electerm client is susceptible to a persistent local-PTY code execution vulnerability due to how it handles imported bookmarks and sync configurations. Users who import bookmark JSON files or configure syncing through platforms like Gist or WebDAV may be at risk. Attackers can exploit this vulnerability by injecting executable fields into bookmarks, allowing malicious code to run when the affected bookmark is accessed or when the sync process is initiated. It poses a significant threat to users' systems and underscores the importance of safeguarding bookmark sources and synchronization settings.
Affected Version(s)
electerm <= 3.8.8
