Arbitrary Command Execution in Electerm Client by Malicious FTP/SFTP Servers
CVE-2026-73224

8.8HIGH

Key Information:

Vendor

Electerm

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73224?

Electerm, an open-source multi-protocol client, is vulnerable to arbitrary command execution when interacting with malicious FTP or SFTP servers. This vulnerability arises due to improper handling of user-supplied folder names within shell commands, enabling attackers to execute unintended commands upon folder downloads. The issue affects versions prior to 3.15.120 and has been resolved in the latest update.

Affected Version(s)

electerm < 3.15.120

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.