{"id":"CVE-2026-45058","aliases":["GHSA-jgg9-rw32-44pj"],"url":"https://o3.security/vulnerability/CVE-2026-45058","summary":"electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark","details":"### Impact\n_Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject `exec*` fields or global config to cause remote code to run when a bookmark is opened or when sync is applied._\n\n### Patches\n\nNot yet\n\n### Workarounds\n- Do not import unsafe data\n\n### References\n- Report / credit: https://github.com/Curly-Haired-Baboon\n- Electerm releases: https://github.com/electerm/electerm/releases","published":"2026-05-28T17:20:41.799Z","modified":"2026-08-12T03:51:41.392141803Z","cvss":null,"epss":{"score":0.00234,"percentile":0.14424,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"electerm","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45058.json"},{"type":"ADVISORY","url":"https://github.com/electerm/electerm/security/advisories/GHSA-jgg9-rw32-44pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45058"},{"type":"PACKAGE","url":"https://github.com/electerm/electerm"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.392141803Z"}}