Security Advisory
CVE-2026-86711
CVSS 7.4
HIGH
Vulnerability Description
electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process.
Published Date
2026-09-08T12:16:59.840
Data Feed
NIST National Vulnerability Database