Description
No description available.
Recommendation
Update the electerm package to the latest compatible version. Followings are version details:
- Affected version(s): >= 3.0.6, < 3.8.8
- Patched version(s): 3.8.8
References
- GHSA-mpm8-cx2p-626q
- CVE-2026-43944
- CWE-20
- CWE-829
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- Electerm Local code through electerm's single-instance socket - CVE-2026-45353
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941
- Electerm runWidget has a path traversal that leads to arbitrary code execution - CVE-2026-43940
- joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas - CVE-2026-48038
You might also like:
- Tags:
- npm
- electerm
Anything's wrong? Let us know Last updated on May 13, 2026


