{"id":"CVE-2026-45787","aliases":["GHSA-g29v-q6h7-76wh"],"url":"https://o3.security/vulnerability/CVE-2026-45787","summary":"electerm's encrypt method not safe enough","details":"electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks. This vulnerability is fixed in 3.9.5.","published":"2026-05-28T17:17:56.385Z","modified":"2026-08-12T03:51:41.134213860Z","cvss":null,"epss":{"score":0.00105,"percentile":0.01205,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"electerm","fixedVersion":"3.9.5"}],"fix":{"url":"https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937","label":"electerm/electerm@9dd8295"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45787.json"},{"type":"ADVISORY","url":"https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45787"},{"type":"FIX","url":"https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.134213860Z"}}