GHSA-fwf6-j56g-m97c · Severity: high · Ecosystem: npm — Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a malicious SSH server, compromised remote host, or malicious plugin rendering terminal content) can thus achieve arbitrary code execution or local file access on the victim's machine, requiring only that the victim clicks a displayed link. At time of publication, there are no publicly available patches.
Conclusion & alert: CVE-2026-43941 is rated Moderate Risk (40.5/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.05% | 0.02% | -0.03% |
| 2 | 2026-05-08 | — | 0.05% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.6 | 3.1 | CRITICAL |
|
2.8 | 6.0 | [email protected] |
GHSA-fwf6-j56g-m97c · Severity: high · Ecosystem: npm — Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| electerm_project | electerm | <= 3.8.15 | cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/electerm/electerm/security/advisories/GHSA-fwf6-j56g-m97c | Vendor Advisory Mitigation |