Description
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters.
Recommendation
Update the xterm package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.10.0, < 3.10.1 >= 3.9.0, < 3.9.2 < 3.8.1** Patched version(s): **3.10.1 3.9.2 3.8.1**
References
- GHSA-mc23-976p-j42x
- access.redhat.com
- www.securityfocus.com
- CVE-2019-0542
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin - CVE-2023-22621
- angular-base64-upload vulnerable to unauthenticated remote code execution - CVE-2024-42640
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- LiquidJS is Vulnerable to Remote Code Execution - CVE-2026-45618
You might also like:
- Tags:
- npm
- xterm
Anything's wrong? Let us know Last updated on March 07, 2023


