9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.
AI Analysis
Arbitrary local code execution via deep links, CLI options, or crafted shortcuts
Basic Information
ID
CVE-2026-43944
Source
GitHub_M
Published
May 8, 2026 at 03:08
Affected Product
Vendor
electerm
Product
electerm
Version
>= 3.0.6, < 3.8.15
Affected Versions
electerm electerm >= 3.0.6, < 3.8.15
CWE Classification
AI Assessment
AI Score
9.4 / 10
AI Severity
Critical
Vendor
electerm
Product
electerm
Version
3.0.6 to 3.8.14