Electerm Unvalidated Shell.openExternal Vulnerability Allowing Arbitrary Code Execution and Local File Access

Vulnerability

A vulnerability in Electerm's terminal hyperlink handler allows arbitrary code execution and local file access. In versions through 3.8.15, the hyperlink handler passes clicked URLs directly to shell.openExternal without validating the protocol. This flaw can be exploited by an attacker controlling terminal output, such as through a malicious SSH server or compromised remote host. The exploitation requires the victim to click a displayed link. At the time of publication, no patches are available.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution or unauthorized access to local files on the victim's machine.

Remediation

Until a patch is released, users should avoid clicking links in the terminal when connected to untrusted servers. It is also advisable to disable hyperlink rendering in Electerm's terminal settings, use a terminal multiplexer like tmux that filters URI schemes, or run Electerm in a restricted environment that limits protocol handler execution.

Added: May 8, 2026, 4:24 AM
Updated: May 8, 2026, 4:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
8.3
relevance
7.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.