PT-2026-87037 · Electerm+1 · Electerm

·

CVE-2026-86711

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v4.0

7.5

High

VectorAV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86711
GHSA-QC8J-6JR2-QR32

Affected Products

Electerm