What is CVE-2026-73224?
CVE-2026-73224 is a vulnerability in the open-source electerm terminal/SSH/FTP client. Before version 3.15.120, a malicious FTP or SFTP server can execute arbitrary commands via the 'calcLocal' function if a user downloads a crafted folder and invokes 'Properties' followed by 'Calculate Size'. Upgrading to the latest version is strongly advised.
Azərbaycanca: CVE-2026-73224, electerm açıq mənbəli terminal/SSH/FTP müştərisinə təsir edən boşluqdur. 3.15.120 versiyasından əvvəl, istifadəçi zərərli FTP/SFTP serverindən hazırlanmış qovluğu yüklədikdə və 'Properties' -> 'Calculate Size' əməliyyatını çağırdıqda, 'calcLocal' funksiyası vasitəsilə uzaqdan əmr icrası mümkündür. Təhlükəsizlik üçün dərhal proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of electerm are affected by CVE-2026-73224?
CVE-2026-73224 affects all versions of electerm prior to version 3.15.120.
What user action is required to trigger this vulnerability?
The user must download a crafted folder from a malicious FTP/SFTP server and then invoke 'Calculate Size' from the 'Properties' menu.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.