{"id":"GHSA-38j7-23hf-9mhc","summary":"electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling","details":"### Impact\n\nA path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in `path.join()` with the user-selected download directory without sanitization.\n\nA malicious SSH server or remote shell process can send a specially crafted filename such as `../escaped.txt` to escape the user-selected download directory and write files to arbitrary locations on the user's filesystem, subject to process permissions.\n\n**Attack scenario:**\n1. User connects to a malicious SSH server\n2. Attacker initiates a Zmodem or Trzsz file transfer\n3. Attacker supplies a traversal filename (e.g., `../../.bashrc`, `../escaped.txt`)\n4. User accepts the transfer and selects a download directory\n5. File is written outside the selected directory, potentially overwriting sensitive files\n\n**Affected components:**\n- `src/app/server/zmodem.js` - `prepareReceiveFile()` at line 736\n- `src/app/server/trzsz.js` - `getUniqueFilePath()` at line 559, `openSaveFile()` callback, and `savedFilePaths` mapping\n\n### Patches\n\n- https://github.com/electerm/electerm/commit/fde153d677a170c5816368f6586647f3af4ef284\n\n### Workarounds\n\n\nIf upgrading is not immediately possible, users can mitigate this vulnerability by:\n1. Only connecting to trusted SSH servers\n2. Rejecting or canceling any incoming Zmodem or Trzsz file transfers from untrusted sources\n3. Avoiding the use of Zmodem (`sz`/`rz`) and Trzsz (`trz`/`tsz`) commands on untrusted servers","aliases":["CVE-2026-49253"],"modified":"2026-07-02T19:41:33.209044Z","published":"2026-07-02T19:20:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-02T19:20:20Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/electerm/electerm/security/advisories/GHSA-38j7-23hf-9mhc"},{"type":"WEB","url":"https://github.com/electerm/electerm/commit/fde153d677a170c5816368f6586647f3af4ef284"},{"type":"PACKAGE","url":"https://github.com/electerm/electerm"}],"affected":[{"package":{"name":"electerm","ecosystem":"npm","purl":"pkg:npm/electerm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.11"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-38j7-23hf-9mhc/GHSA-38j7-23hf-9mhc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L"}]}