Xtermjs is a terminal emulation library for web browsers that enables in-browser command-line interfaces and SSH clients, with observed vulnerabilities centered on its code-generation and dynamic-execution mechanisms. The durable signal is code-injection weakness in terminal rendering and command handling, a class of flaw that recurs naturally from the product's role in bridging user input to executable contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xtermjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0542HIGH A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js. | Jan 9, 2019 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xtermjs.
Media articles that mention a CVE ID that affects a product developed by Xtermjs — matched by CVE ID, not by vendor name.