Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jgg9-rw32-44pj | Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark |
Sat, 30 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Electerm
Electerm electerm |
|
| Vendors & Products |
Electerm
Electerm electerm |
Thu, 28 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied. | |
| Title | electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark | |
| Weaknesses | CWE-345 CWE-494 CWE-915 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-30T02:04:03.353Z
Reserved: 2026-05-08T18:07:27.342Z
Link: CVE-2026-45058
Updated: 2026-05-30T02:03:59.266Z
Status : Deferred
Published: 2026-05-28T18:16:34.313
Modified: 2026-06-01T18:38:18.703
Link: CVE-2026-45058
No data.
OpenCVE Enrichment
Updated: 2026-05-28T19:30:16Z
Github GHSA