Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

Electerm Local code through electerm's single-instance socket

GHSA-7p5m-v798-f8vv · CVE-2026-45353

Published · Modified

Description

Impact

Local code execution without UI interaction: any same-user process can send a JSON payload to electerm's single-instance socket/pipe, causing the app to create tabs and potentially spawn attacker-controlled local processes. Affects electerm single-instance installs on the machine.

Patches

Workarounds

  • Do not run unsafe command

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes