# CVE-2026-45058

## Summary

- **CVE ID:** CVE-2026-45058
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-94, CWE-345, CWE-494, CWE-915
- **Published:** May 28, 2026
- **Last Modified:** May 30, 2026

## Description

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject exec* fields or global config to cause remote code to run when a bookmark is opened or when sync is applied.

## Affected Products

- electerm — electerm (<= 3.8.8)

## References

- [CNA](https://github.com/electerm/electerm/security/advisories/GHSA-jgg9-rw32-44pj)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 14.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._