Arbitrary Command Execution in Electerm Product by Vendor Electerm
CVE-2026-86711
7.5HIGH
What is CVE-2026-86711?
Electerm, prior to version 5.3.15, is susceptible to a serious vulnerability that exposes over 40 main-process functions via an unvalidated Electron IPC (Inter-Process Communication) handler. This lack of function-name allowlist and sender validation enables the renderer-side script execution to invoke critical functions, such as openFileWithEditor, with arbitrary arguments. This could lead to the execution of system commands from the main process, posing significant security risks. It is crucial for users of Electerm to update to the latest version to mitigate this issue.
Affected Version(s)
electerm 0 < 5.3.15
