CVE-2026-43941Disclosure(electerm_project / electerm)

LOWCVSS 9.6 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch electerm_project electerm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim's machine, requiring only that the victim clicks a displayed link. At time of publication, there are no publicly available patches.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electerm

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-14)
  • 6 total mentions across 2 days

Affected systems

Products
electerm

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-05-10: 1Mentions · 2026-05-14: 5Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 405-1005-14
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-101
General1
2026-05-145
Disclosure4General1
Full discourse6 posts
  • CVE@CVEnew
    General

    CVE-2026-43941 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes a… https://www.cve.org/CVERecord?id=CVE-2026-43941

    Post summary

    CVE-2026-43941 is referenced as a vulnerability in Electerm’s terminal hyperlink handling, but no PoC, exploit, patch, or detailed technical information is provided.

    00020149
    57.8K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-43941 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE‑2026‑43941 as critical (CVSS 9.6/3.1) but provides no PoC, exploit code, or mitigation details.

    1000028
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-43941 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE-2026-43941 as a critical vulnerability with a high CVSS score, but it does not provide detailed technical exploitable information, any PoC, or mitigation guidance.

    1000024
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-43941 (CVSS 9.6) — multiple products. CVE: CVE-2026-43941 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE-2026-43941 with a CVSS score of 9.6 and critical severity, but provides no PoC, exploit code, or evidence of active exploitation.

    1000022
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-43941 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client.

    Post summary

    CVE-2026-43941 is publicly disclosed as a critical vulnerability in the Electerm client, with detailed CVSS scoring but no evidence of exploitation, PoC, or patches.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43941-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text is a link to an advisory and hashtags, with no further information on the CVE’s technical details, exploitation status, or mitigation.

    0000019
    210 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelecterm_projectelecterm---

Explore more