Remote Code Execution Vulnerability in Electerm Terminal Client
CVE-2026-73226
8.8HIGH
What is CVE-2026-73226?
Electerm, an open-source terminal client that supports various protocols, is affected by a vulnerability that allows authenticated WebSocket clients to exploit unintended internal functions. This flaw exists in the upgrade-func and handleFs methods, enabling users to invoke commands, manipulate the filesystem, or disrupt service. It is crucial for users of Electerm versions prior to 3.15.186 to upgrade to mitigate these risks.
Affected Version(s)
electerm < 3.15.186
