Security Flaw in Electerm Open-Sourced Terminal Client
CVE-2026-73223

8.1HIGH

Key Information:

Vendor

Electerm

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73223?

Electerm is an open-sourced terminal client that supports various protocols including SSH and SFTP. Prior to version 3.15.120, it was discovered that a malicious SFTP server could exploit a flaw in the application's file handling by transmitting an attacker-controlled filename. This filename, used in the 'editWithSystemEditor' function, was incorrectly interpolated into a file path without adequate sanitization. As a result, the attacker could write harmful content outside the designated temporary directory. This serious flaw, now addressed in version 3.15.120, highlights the importance of proper input validation to enhance security and prevent unauthorized access.

Affected Version(s)

electerm < 3.15.120

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.