Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-43944

36
FAUCET Score

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.

First published: May 8, 2026Last modified: May 13, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.6, < 3.8.15CPE matchmatch criteria
cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.4CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 33rd percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: electermFixed in: 3.8.8

Vendor Advisories (1)

npmGHSA-mpm8-cx2p-626qcritical

Electerm users can run dangrous code through link or command line

May 8, 2026

References

github.com / electerm/electerm/commit/0599e67069b00e376a2e962649aaad6096e63507
github.com / electerm/electerm/commit/8a6a17951e96d715f5a231532bbd8303fe208700
Patch
github.com / electerm/electerm/commit/a79e06f4a1f0ac6376c3d2411ef4690fa0377742
Patch
github.com / electerm/electerm/releases/tag/v3.8.15
Release Notes
github.com / electerm/electerm/security/advisories/GHSA-mpm8-cx2p-626q
MitigationPatchVendor Advisory