CVE-2026-73224

8.8

electerm · electerm

A command injection vulnerability in the electerm client allows attackers to execute arbitrary OS commands through improper neutralization of special elements.

Executive summary

An OS command injection vulnerability in the electerm client, rated at 8.8, allows an attacker to execute arbitrary commands on the host system.

Vulnerability

The vulnerability is an OS command injection flaw arising from the improper handling of input. It is remotely exploitable and requires user interaction, but does not require authentication to trigger.

Business impact

Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the user running the electerm client. This could lead to a full compromise of the local machine, including the theft of SSH keys, stored credentials, and lateral movement within the network, justifying the 8.8 CVSS score.

Remediation

Immediate Action: Update the electerm client to version 3.15.120 or later to apply the necessary security fixes.

Proactive Monitoring: Monitor for unexpected child processes being spawned by the electerm application or unusual outbound network connections originating from the host.

Compensating Controls: Restrict the execution environment of the client by utilizing containerization or sandboxing, and ensure the host operating system is hardened against unauthorized command execution.

Exploitation status

Public Exploit Available: false

Analyst recommendation

All users of the electerm client must upgrade to version 3.15.120 immediately to mitigate the risk of remote command execution. Given the potential for full system compromise, this update should be treated as a high-priority maintenance task for all workstations and servers running the affected software.

More electerm CVEs