Arbitrary Command Execution in Electerm Product by Vendor Electerm
CVE-2026-86711

7.5HIGH

Key Information:

Vendor

Electerm

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86711?

Electerm, prior to version 5.3.15, is susceptible to a serious vulnerability that exposes over 40 main-process functions via an unvalidated Electron IPC (Inter-Process Communication) handler. This lack of function-name allowlist and sender validation enables the renderer-side script execution to invoke critical functions, such as openFileWithEditor, with arbitrary arguments. This could lead to the execution of system commands from the main process, posing significant security risks. It is crucial for users of Electerm to update to the latest version to mitigate this issue.

Affected Version(s)

electerm 0 < 5.3.15

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.