CRITICALCVSS 9.1Vulnerability
CVE-2026-45787
### Impact _Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks._ ### Patches - https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937 ### Workarounds - No ### References - Report / credit: https://github.com/Curly-Haired-Baboon - Electerm releases: https://github.com/electerm/electerm/releases
Properties
- summary
- electerm's encrypt method not safe enough
- severity
- CRITICAL
- cvss_score
- 9.1
- epss_score
- 0.00105
- ghsa_published
- 2026-05-14T20:30:04Z
- source_url
- https://github.com/advisories/GHSA-g29v-q6h7-76wh
- ghsa_updated
- 2026-05-14T20:30:05Z
- ghsa_id
- GHSA-g29v-q6h7-76wh
- cve_id
- CVE-2026-45787
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.01214
Related Entities (9)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]npm/electerm
AFFECTS (1)
→[Software]npm/electerm
HAS_WEAKNESS (5)
→[Weakness]Use of Password Hash With Insufficient Computational Effort
→[Weakness]Inadequate Encryption Strength
→[Weakness]Missing Support for Integrity Check
→[Weakness]Generation of Predictable IV with CBC Mode
→[Weakness]Use of a One-Way Hash without a Salt
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph