UNKNOWN npm
electerm's encrypt method not safe enough
GHSA-g29v-q6h7-76wh · CVE-2026-45787
Published · Modified
Description
Impact
Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks.
Patches
Workarounds
- No
References
- Report / credit: https://github.com/Curly-Haired-Baboon
- Electerm releases: https://github.com/electerm/electerm/releases
References
- WEB https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-45787
- WEB https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937
- PACKAGE https://github.com/electerm/electerm
- WEB https://github.com/electerm/electerm/releases/tag/v3.9.5
Ready to move
Start Securing
Free, no credit card | First findings in minutes