Electerm Local code through electerm's single-instance socket
Critical severity
GitHub Reviewed
Published
May 12, 2026
in
electerm/electerm
•
Updated May 14, 2026
Description
Published to the GitHub Advisory Database
May 14, 2026
Reviewed
May 14, 2026
Last updated
May 14, 2026
Impact
Local code execution without UI interaction: any same-user process can send a JSON payload to electerm's single-instance socket/pipe, causing the app to create tabs and potentially spawn attacker-controlled local processes. Affects electerm single-instance installs on the machine.
Patches
Workarounds
References
References