CVE-2026-86711
Severity CVSS v4.0:
HIGH
Type:
CWE-749
Exposed Dangerous Method or Function
Publication date:
08/09/2026
Last modified:
08/09/2026
Description
electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process.
Impact
Base Score 4.0
7.50
Severity 4.0
HIGH
Base Score 3.x
7.40
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/electerm/electerm
- https://github.com/electerm/electerm/blob/v5.3.5/src/app/lib/ipc.js
- https://github.com/electerm/electerm/commit/b1f880534b8ae066c5d25bbf291ca7437e052750
- https://github.com/electerm/electerm/issues/4509
- https://github.com/electerm/electerm/releases/tag/v5.3.15
- https://github.com/electerm/electerm/security/advisories/GHSA-qc8j-6jr2-qr32
- https://www.vulncheck.com/advisories/electerm-before-5.3.15-arbitrary-command-execution-via-unvalidated-runglobalasync-ipc-bridge


