Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-86711

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-749 Exposición de método o función peligrosos
Fecha de publicación:
08/09/2026
Última modificación:
08/09/2026

Descripción

*** Pendiente de traducción *** electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process.