CVE Explorer
CVE-2026-43942
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is accessible from any JavaScript running in the renderer (e.g., via the DevTools console or a compromised webview context). An attacker who achieves any JavaScript execution within the renderer can trivially e
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-312","description":"CWE-312: Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"electerm","vendor":"electerm","versions":[{"status":"affected","version":"<= 3.8.15"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-312","description":"CWE-312: Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/electerm/electerm/security/advisories/GHSA-37j4-88rp-2f6h","tags":["x_refsource_CONFIRM"],"url":"https://github.com/electerm/electerm/security/advisories/GHSA-37j4-88rp-2f6h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f69723beb78ea32e9fe33e3ab22765ac44e16251e0c4c4e124c1a901621f2e29 · sha256:8d3eaa07a64b0113… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.