Description
The getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is accessible from any JavaScript running in the renderer (e.g., via the DevTools console or a compromised webview context).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.8.15
References
Could your website be exposed too?
SmartScanner can check your website for Electerm's full process.env exposed to renderer via window.pre.env and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941
- FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection - CVE-2026-43945
- electerm has Command Injection via runLinux funtion - CVE-2026-41501
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - CVE-2026-34751


