Description
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters.
Recommendation
Update the xterm package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.10.0, < 3.10.1 >= 3.9.0, < 3.9.2 < 3.8.1** Patched version(s): **3.10.1 3.9.2 3.8.1**
References
Could your website be exposed too?
SmartScanner can check your website for xterm vulnerable to remote code execution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin - CVE-2023-22621
- angular-base64-upload vulnerable to unauthenticated remote code execution - CVE-2024-42640
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- LiquidJS is Vulnerable to Remote Code Execution - CVE-2026-45618
You might also like:
See something that needs correcting? Let us knowUpdated March 07, 2023


