Security Flaw in Electerm Open-Sourced Terminal Client
CVE-2026-73223
8.1HIGH
What is CVE-2026-73223?
Electerm is an open-sourced terminal client that supports various protocols including SSH and SFTP. Prior to version 3.15.120, it was discovered that a malicious SFTP server could exploit a flaw in the application's file handling by transmitting an attacker-controlled filename. This filename, used in the 'editWithSystemEditor' function, was incorrectly interpolated into a file path without adequate sanitization. As a result, the attacker could write harmful content outside the designated temporary directory. This serious flaw, now addressed in version 3.15.120, highlights the importance of proper input validation to enhance security and prevent unauthorized access.
Affected Version(s)
electerm < 3.15.120
