Description
The getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is accessible from any JavaScript running in the renderer (e.g., via the DevTools console or a compromised webview context).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.8.15
References
Related Issues
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941
- FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection - CVE-2026-43945
- electerm has Command Injection via runLinux funtion - CVE-2026-41501
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - CVE-2026-34751
You might also like:
- Tags:
- npm
- electerm
Anything's wrong? Let us know Last updated on May 08, 2026


