CVE-2026-86711
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-749
Exposición de método o función peligrosos
Fecha de publicación:
08/09/2026
Última modificación:
08/09/2026
Descripción
*** Pendiente de traducción *** electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process.
Impacto
Puntuación base 4.0
7.50
Gravedad 4.0
ALTA
Puntuación base 3.x
7.40
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/electerm/electerm
- https://github.com/electerm/electerm/blob/v5.3.5/src/app/lib/ipc.js
- https://github.com/electerm/electerm/commit/b1f880534b8ae066c5d25bbf291ca7437e052750
- https://github.com/electerm/electerm/issues/4509
- https://github.com/electerm/electerm/releases/tag/v5.3.15
- https://github.com/electerm/electerm/security/advisories/GHSA-qc8j-6jr2-qr32
- https://www.vulncheck.com/advisories/electerm-before-5.3.15-arbitrary-command-execution-via-unvalidated-runglobalasync-ipc-bridge


