CRITICALCVSS 9.1Vulnerability

CVE-2026-45787

### Impact _Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks._ ### Patches - https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937 ### Workarounds - No ### References - Report / credit: https://github.com/Curly-Haired-Baboon - Electerm releases: https://github.com/electerm/electerm/releases

Properties

summary
electerm's encrypt method not safe enough
severity
CRITICAL
cvss_score
9.1
epss_score
0.00105
ghsa_published
2026-05-14T20:30:04Z
source_url
https://github.com/advisories/GHSA-g29v-q6h7-76wh
ghsa_updated
2026-05-14T20:30:05Z
ghsa_id
GHSA-g29v-q6h7-76wh
cve_id
CVE-2026-45787
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
epss_percentile
0.01214

Related Entities (9)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/electerm

AFFECTS (1)

[Software]npm/electerm

HAS_WEAKNESS (5)

[Weakness]Use of Password Hash With Insufficient Computational Effort
[Weakness]Inadequate Encryption Strength
[Weakness]Missing Support for Integrity Check
[Weakness]Generation of Predictable IV with CBC Mode
[Weakness]Use of a One-Way Hash without a Salt

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph