{"id":"GHSA-g29v-q6h7-76wh","summary":"electerm's encrypt method not safe enough","details":"### Impact\n_Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks._\n\n### Patches\n\n- https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937\n\n### Workarounds\n\n- No\n\n### References\n- Report / credit: https://github.com/Curly-Haired-Baboon\n- Electerm releases: https://github.com/electerm/electerm/releases","aliases":["CVE-2026-45787"],"modified":"2026-06-09T10:30:11.459761231Z","published":"2026-05-14T20:30:04Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-14T20:30:04Z","nvd_published_at":"2026-05-28T18:16:35Z","cwe_ids":["CWE-326","CWE-329","CWE-353","CWE-759","CWE-916"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45787"},{"type":"WEB","url":"https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937"},{"type":"PACKAGE","url":"https://github.com/electerm/electerm"},{"type":"WEB","url":"https://github.com/electerm/electerm/releases/tag/v3.9.5"}],"affected":[{"package":{"name":"electerm","ecosystem":"npm","purl":"pkg:npm/electerm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.9.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g29v-q6h7-76wh/GHSA-g29v-q6h7-76wh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}