Vulnerabilities/

electerm has Command Injection in File System Operations (rmrf, mv, cp)

Severity:
High

Description

A command injection vulnerability exists in electerm’s file system operations (rmrf, mv, cp) in src/app/lib/fs.js. These functions construct shell commands by interpolating file paths directly into command strings without escaping shell metacharacters.

Recommendation

Update the electerm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
electerm
Anything's wrong? Let us know Last updated on July 02, 2026