PT-2026-70878 · Electerm · Electerm

CVE-2026-73226

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions electerm versions prior to 3.15.186
Description An authenticated WebSocket client can invoke unintended internal functions due to a missing method-name allowlist. By controlling func values within the upgrade-func in src/app/server/dispatch-center.js and handleFs in src/app/server/fs.js, an attacker can expose Upgrade and fsExport methods. This allows for the execution of commands, opening of files, mutation of the filesystem, or termination of the process.
Recommendations Update to version 3.15.186.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73226
GHSA-8CHW-JWC5-8587

Affected Products

Electerm