{"id":"GHSA-v5ff-xmfp-p245","summary":"electerm has Command Injection in File System Operations (rmrf, mv, cp)","details":"### Impact\n\nA command injection vulnerability exists in electerm's file system operations (`rmrf`, `mv`, `cp`) in `src/app/lib/fs.js`. These functions construct shell commands by interpolating file paths directly into command strings without escaping shell metacharacters.\n\n**Vulnerable functions:**\n- `rmrf()` - Uses `rm -rf \"${path}\"` (double quotes, vulnerable to `\"` injection)\n- `mv()` - Uses `mv '${from}' '${to}'` (single quotes, vulnerable to `'` injection)\n- `cp()` - Uses `cp -r \"${from}\" \"${to}\"` (double quotes, vulnerable to `\"` injection)\n\n**Attack scenario:**\n1. Attacker controls a malicious SSH/SFTP server\n2. Server lists files with shell metacharacters in names (e.g., `file\"$(touch /tmp/pwned)\"`)\n3. Victim connects to the server and performs file operations (remote-to-local transfer, rename on conflict, etc.)\n4. The malicious filename is passed to `rmrf()`, `mv()`, or `cp()` without sanitization\n5. Shell metacharacters break out of the quoted argument and execute arbitrary commands\n\n**Impact includes:**\n- Arbitrary command execution as the electerm desktop user\n- Data exfiltration, malware installation, or system compromise\n- Both POSIX (bash) and Windows (PowerShell) platforms are affected\n\n### Patches\n\n- https://github.com/electerm/electerm/commit/aa778818843b9c083bd711cd04644d102fcb5a42\n\n### Workarounds\n\nIf upgrading is not immediately possible, users can mitigate this vulnerability by:\n1. Only connecting to trusted SSH/SFTP servers\n2. Avoiding remote-to-local file transfers from untrusted sources\n3. Not using the \"rename on conflict\" option when downloading folders from untrusted servers\n4. Manually verifying filenames before performing file operations","aliases":["CVE-2026-49255"],"modified":"2026-07-02T19:41:33.135414Z","published":"2026-07-02T19:22:31Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-02T19:22:31Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/electerm/electerm/security/advisories/GHSA-v5ff-xmfp-p245"},{"type":"WEB","url":"https://github.com/electerm/electerm/commit/aa778818843b9c083bd711cd04644d102fcb5a42"},{"type":"PACKAGE","url":"https://github.com/electerm/electerm"}],"affected":[{"package":{"name":"electerm","ecosystem":"npm","purl":"pkg:npm/electerm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.11"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.11.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v5ff-xmfp-p245/GHSA-v5ff-xmfp-p245.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}