High severity8.8NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-73226
CVE-2026-73226
Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handleFs in src/app/server/fs.js, exposing Upgrade and fsExport methods that can execute commands, open files, mutate the filesystem, or terminate the process. This issue is fixed in version 3.15.186.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.