← Back
CVE-2026-73224
high
CVSS 8.8
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user do...
Summary
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/c...
AI summary openai / gpt-4o
electermはオープンソースのターミナル/SSH/SFTP/Telnet/などのクライアントです。バージョン3.15.120より前には、悪意のあるFTPまたはSFTPサーバーがコマンドを任意に実行できる脆弱性があります。この問題はバージョン3.15.120で修正されています。
❓ What is the problem
electerm において、悪意のあるFTPまたはSFTPサーバーが任意のコマンドを実行できる脆弱性です。
📍 Affected scope
バージョン3.15.120未満のelecterm
🔥 Severity
悪意のあるFTP/SFTPサーバーによって任意のコマンドが実行される可能性があります。
🔧 How to fix
バージョンを3.15.120に更新してください。
🛡️ Workaround
バージョンを更新するまで信頼できないサーバーに接続しないでください。
🔍 Detection
脆弱なバージョンを使用しているかを確認し、修正パッチの適用有無を検証してください。
References
- web [email protected]
- web [email protected]
- web [email protected]