Confidentiality and Integrity Failures in Electerm SSH and Terminal Client
CVE-2026-45787
6MEDIUM
What is CVE-2026-45787?
Electerm, an open-source terminal and SSH client, is impacted by a vulnerability where deterministic AES-192-CBC is employed with fixed zero Initialization Vector (IV) and a constant Key Derivation Function (KDF) salt. This configuration compromises the confidentiality and integrity of synced bookmark and profile data. Malicious actors can exploit this by cracking common passwords across different installations, enabling them to perform undetected modifications through ciphertext bit-flips to alter configuration and bookmark settings. Users are advised to update to version 3.9.5, which addresses these vulnerabilities.
Affected Version(s)
electerm < 3.9.5
