Arbitrary Command Execution in Electerm Client by Malicious FTP/SFTP Servers
CVE-2026-73224
8.8HIGH
What is CVE-2026-73224?
Electerm, an open-source multi-protocol client, is vulnerable to arbitrary command execution when interacting with malicious FTP or SFTP servers. This vulnerability arises due to improper handling of user-supplied folder names within shell commands, enabling attackers to execute unintended commands upon folder downloads. The issue affects versions prior to 3.15.120 and has been resolved in the latest update.
Affected Version(s)
electerm < 3.15.120
