PT-2026-70879 · Electerm · Electerm

CVE-2026-73227

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions electerm versions prior to 3.15.120
Description A flaw exists where a malicious RDP server can write attacker-controlled content outside the designated save directory. This occurs because the RDP clipboard download path in src/client/components/rdp/file-transfer.js passes the server-controlled fileInfo.name variable to the osResolve() function without proper sanitization.
Recommendations Update to version 3.15.120.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73227
GHSA-GM6Q-5VPX-3MWF

Affected Products

Electerm