{"id":"CVE-2026-45058","aliases":["GHSA-jgg9-rw32-44pj"],"url":"https://o3.security/vulnerability/CVE-2026-45058","summary":"electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark","details":"electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.","published":"2026-05-28T17:20:41.799Z","modified":"2026-08-12T03:51:41.392141803Z","cvss":null,"epss":{"score":0.00234,"percentile":0.14261,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"electerm","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45058.json"},{"type":"ADVISORY","url":"https://github.com/electerm/electerm/security/advisories/GHSA-jgg9-rw32-44pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45058"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.392141803Z"}}