Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Description
Published to the GitHub Advisory Database
May 14, 2026
Reviewed
May 14, 2026
Published by the National Vulnerability Database
May 28, 2026
Last updated
Jun 9, 2026
Impact
Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject
exec*fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.Patches
Not yet
Workarounds
References
References