CVE-2026-43940Patch(electerm_project / electerm)

MEDIUMCVSS 8.4 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch electerm_project electerm systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation. Because runWidget is exposed to the renderer process via an asynchronous IPC handler with no input validation, an attacker who achieves JavaScript execution inside the renderer (for example, through a malicious plugin or a cross‑site scripting flaw in the built‑in webview) can abuse a path traversal (../) to load and execute an arbitrary JavaScript file anywhere on the victim’s filesystem. This gives the attacker local code execution with the full privileges of the electerm process, leading to complete system compromise. This issue has been patched in version 3.7.16.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-829

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electerm

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-27)
  • 4 total mentions across 3 days

Affected systems

Products
electerm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-10: 1Mentions · 2026-05-27: 2Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-05-27: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-27: 205-0805-1005-27
Signal classification3 categories
Patch
250.0%
Active Exploitation
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
Active Exploitation1
2026-05-101
Disclosure1
2026-05-272
Patch2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-43940 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widg… https://www.cve.org/CVERecord?id=CVE-2026-43940

    Post summary

    A vulnerability in the open‑source terminal client electerm was identified in the runWidget function before version 3.7.16, as reported by CVE‑2026‑43940.

    00010143
    57.5K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    Critical 9.8 path traversal in electerm (npm). CVE-2026-43940: unsanitised widget IDs in runWidget() let attackers traverse the filesystem remotely — no auth, no interaction needed. Update to v3.7.16 now. https://secalerts.co/vulnerability/GHSA-f77v-9vpc-6pjm https://t.co/PgSa9WkI6w

    Post summary

    The tweet announces a critical 9.8 path‑traversal vulnerability in electerm (CVE‑2026‑43940) and provides a patch update (v3.7.16), but does not mention a PoC, exploit code, or active exploitation.

    0000080
    826 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🚨 CVE-2026-43940 in electerm (npm): critical 9.8 path traversal — no auth, no interaction needed. Full RCE potential via unsanitised widget paths. Patch to v3.7.16 now. https://secalerts.co/vulnerability/CVE-2026-43940

    Post summary

    An alert highlights CVE-2026-43940 as a path traversal that could lead to full remote code execution; a patch to version 3.7.16 is now available.

    0000072
    826 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Active Exploitation

    Today (Fri, May 8): 1 KEV, 6 critical CVEs. LiteLLM SQLi (KEV) earlier. Long tail: - Open WebUI: 7 advisories, LDAP empty-password bypass (CVE-2026-44551, 9.1) - Electerm SSH client: 4 RCE-class bugs (CVE-2026-43940, 9.8) - PrestaShop stored XSS (CVE-2026-44212, 9.3)

    Post summary

    The post announces six critical CVEs, including a KEV for LiteLLM SQLi and an LDAP empty‑password bypass, signaling active exploitation, yet provides no PoC or patch information.

    0000077
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelecterm_projectelecterm---

Explore more