原始 OSV JSON{
"id": "GHSA-v5ff-xmfp-p245",
"aliases": [
"CVE-2026-49255"
],
"details": "### Impact\n\nA command injection vulnerability exists in electerm's file system operations (`rmrf`, `mv`, `cp`) in `src/app/lib/fs.js`. These functions construct shell commands by interpolating file paths directly into command strings without escaping shell metacharacters.\n\n**Vulnerable functions:**\n- `rmrf()` - Uses `rm -rf \"${path}\"` (double quotes, vulnerable to `\"` injection)\n- `mv()` - Uses `mv '${from}' '${to}'` (single quotes, vulnerable to `'` injection)\n- `cp()` - Uses `cp -r \"${from}\" \"${to}\"` (double quotes, vulnerable to `\"` injection)\n\n**Attack scenario:**\n1. Attacker controls a malicious SSH/SFTP server\n2. Server lists files with shell metacharacters in names (e.g., `file\"$(touch /tmp/pwned)\"`)\n3. Victim connects to the server and performs file operations (remote-to-local transfer, rename on conflict, etc.)\n4. The malicious filename is passed to `rmrf()`, `mv()`, or `cp()` without sanitization\n5. Shell metacharacters break out of the quoted argument and execute arbitrary commands\n\n**Impact includes:**\n- Arbitrary command execution as the electerm desktop user\n- Data exfiltration, malware installation, or system compromise\n- Both POSIX (bash) and Windows (PowerShell) platforms are affected\n\n### Patches\n\n- https://github.com/electerm/electerm/commit/aa778818843b9c083bd711cd04644d102fcb5a42\n\n### Workarounds\n\nIf upgrading is not immediately possible, users can mitigate this vulnerability by:\n1. Only connecting to trusted SSH/SFTP servers\n2. Avoiding remote-to-local file transfers from untrusted sources\n3. Not using the \"rename on conflict\" option when downloading folders from untrusted servers\n4. Manually verifying filenames before performing file operations",
"summary": "electerm has Command Injection in File System Operations (rmrf, mv, cp)",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "3.11.11"
}
]
}
],
"package": {
"name": "electerm",
"ecosystem": "npm"
},
"database_specific": {
"last_known_affected_version_range": "<= 3.11.0"
}
}
],
"modified": "2026-07-02T19:22:31Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"published": "2026-07-02T19:22:31Z",
"references": [
{
"url": "https://github.com/electerm/electerm/security/advisories/GHSA-v5ff-xmfp-p245",
"type": "WEB"
},
{
"url": "https://github.com/electerm/electerm/commit/aa778818843b9c083bd711cd04644d102fcb5a42",
"type": "WEB"
},
{
"url": "https://github.com/electerm/electerm",
"type": "PACKAGE"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2026-07-02T19:22:31Z"
}
}