OSV 1.4.0 · github-reviewed · 修改于 2026-06-09 18:19
发布时间
2026-05-15 04:15
GitHub 审查时间
2026-05-15 04:15
NVD 发布时间
2026-05-29 02:16
源文件
advisories/github-reviewed/2026/05/GHSA-jgg9-rw32-44pj/GHSA-jgg9-rw32-44pj.json
Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.
Not yet