Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark

GHSA-jgg9-rw32-44pj · CVE-2026-45058

Published · Modified

Description

Impact

Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.

Patches

Not yet

Workarounds

  • Do not import unsafe data

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes