Vulnerabilities/

electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling

Severity:
High

Description

A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.

Recommendation

Update the electerm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
electerm
Anything's wrong? Let us know Last updated on July 02, 2026