electerm: electerm_install_script_CommandInjection Vulnerability Report
- Severity:
- High
Description
Command Injection vulnerabilities in electerm:
A command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:150. The runMac() function appends attacker-controlled remote releaseInfo.name directly into an exec("open ...") command without validation.
Recommendation
Update the electerm package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.3.8
- Patched version(s): 3.3.8
References
Related Issues
- Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor - CVE-2026-43943
- Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability - CVE-2026-44211
- ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 - Vulnerability
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
You might also like:
- Tags:
- npm
- electerm
Anything's wrong? Let us know Last updated on May 11, 2026


