PT-2026-38647 · Electerm · Electerm

Osageling

·

Published

2026-05-08

·

Updated

2026-05-14

·

CVE-2026-43941

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electerm versions prior to 3.8.16
Description The terminal hyperlink handler passes any URL clicked in the terminal directly to the shell.openExternal function without protocol validation. An attacker controlling terminal output, such as through a malicious SSH server, compromised remote host, or malicious plugin, can execute arbitrary code or access local files if a victim clicks a crafted link. This occurs because the operating system's default protocol handler executes the URI, which can be abused to trigger dangerous handlers like ms-msdt: and search-ms:, or open local files and network shares via file:// and UNC paths to leak NTLM hashes or exfiltrate data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Do not click on any links displayed in terminal sessions connected to untrusted servers. Disable hyperlink rendering in terminal settings. Run the software in a restricted environment, such as a sandbox, AppArmor, or SELinux, to limit the spawning of protocol handlers.

Open Redirect

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43941
GHSA-FWF6-J56G-M97C

Affected Products

Electerm