High severity7.8GHSA Advisory· Published May 28, 2026· Updated Jun 17, 2026
CVE-2026-45353
CVE-2026-45353
Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
electermnpm | >= 3.0.6, < 3.9.0 | 3.9.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/electerm/electerm/commit/0599e67069b00e376a2e962649aaad6096e63507nvdPatchWEB
- github.com/electerm/electerm/security/advisories/GHSA-7p5m-v798-f8vvnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-7p5m-v798-f8vvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-45353ghsaADVISORY
News mentions
1- Electerm: Three Critical and Medium CVEs Disclosed — Weak Crypto and RCE via Imported BookmarksVypr Intelligence · May 28, 2026