HIGHVulnerability

CVE-2026-73226

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handleFs in src/app/server/fs.js, exposing Upgrade and fsExport methods that can execute commands, open files, mutate the filesystem, or terminate the process. This issue is fixed in version 3.15.186.

Properties

severity
HIGH
score
8.8
epss_score
0.00385
cve_id
CVE-2026-73226
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-11T19:18:52.320
last_modified
2026-09-09T20:55:04.493
epss_percentile
0.31905

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Control of Dynamically-Managed Code Resources

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73226 — Ninja Signal Threat Intelligence | Ninja Signal