Vulnerability Details CVE-2026-43944
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.8%
CVSS Severity
CVSS v3 Score 9.6
Products affected by CVE-2026-43944
-
cpe:2.3:a:electerm_project:electerm:3.0.18
-
cpe:2.3:a:electerm_project:electerm:3.0.6
-
cpe:2.3:a:electerm_project:electerm:3.1.16
-
cpe:2.3:a:electerm_project:electerm:3.1.26
-
cpe:2.3:a:electerm_project:electerm:3.1.6
-
cpe:2.3:a:electerm_project:electerm:3.2.0
-
cpe:2.3:a:electerm_project:electerm:3.3.8
-
cpe:2.3:a:electerm_project:electerm:3.5.6
-
cpe:2.3:a:electerm_project:electerm:3.6.16
-
cpe:2.3:a:electerm_project:electerm:3.6.6
-
cpe:2.3:a:electerm_project:electerm:3.7.16
-
cpe:2.3:a:electerm_project:electerm:3.7.18
-
cpe:2.3:a:electerm_project:electerm:3.7.9
-
cpe:2.3:a:electerm_project:electerm:3.8.6
-
cpe:2.3:a:electerm_project:electerm:3.8.8