High severity8.8NVD Advisory· Published Jan 9, 2019· Updated Jun 17, 2026
CVE-2019-0542
CVE-2019-0542
Description
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
xtermnpm | < 3.8.1 | 3.8.1 |
xtermnpm | >= 3.9.0, < 3.9.2 | 3.9.2 |
xtermnpm | >= 3.10.0, < 3.10.1 | 3.10.1 |
Affected products
2- https://xtermjs.org//xterm.jsv5Range: xterm.js
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-mc23-976p-j42xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-0542ghsaADVISORY
- www.securityfocus.com/bid/106434nvdWEB
- access.redhat.com/errata/RHBA-2019:0959nvdWEB
- access.redhat.com/errata/RHSA-2019:1422nvdWEB
- access.redhat.com/errata/RHSA-2019:2551nvdWEB
- access.redhat.com/errata/RHSA-2019:2552nvdWEB
- github.com/xtermjs/xterm.js/commit/3592c641cd0348e0b698e8a180aea2072c6bcd9aghsaWEB
- github.com/xtermjs/xterm.js/releases/tag/3.8.1ghsaWEB
- github.com/xtermjs/xterm.js/releasesnvd
News mentions
0No linked articles in our index yet.