Description
A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.
Recommendation
Update the electerm package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.11.0
- Patched version(s): 3.11.11
References
Could your website be exposed too?
SmartScanner can check your website for electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Electerm runWidget has a path traversal that leads to arbitrary code execution - CVE-2026-43940
- i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns - CVE-2026-41691
- SillyTavern has a Path Traversal issue - CVE-2026-44650
- Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read - CVE-2026-40163


