electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling
- Severity:
- High
Description
A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.
Recommendation
Update the electerm package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.11.0
- Patched version(s): 3.11.11
References
Related Issues
- Electerm runWidget has a path traversal that leads to arbitrary code execution - CVE-2026-43940
- i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns - CVE-2026-41691
- SillyTavern has a Path Traversal issue - CVE-2026-44650
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163
You might also like:
- Tags:
- npm
- electerm
Anything's wrong? Let us know Last updated on July 02, 2026


