CVE-2026-49253
Published:July 02, 2026
Updated:July 05, 2026
Impact A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in "path.join()" with the user-selected download directory without sanitization. A malicious SSH server or remote shell process can send a specially crafted filename such as "../escaped.txt" to escape the user-selected download directory and write files to arbitrary locations on the user's filesystem, subject to process permissions. Attack scenario: 1. User connects to a malicious SSH server 2. Attacker initiates a Zmodem or Trzsz file transfer 3. Attacker supplies a traversal filename (e.g., "../../.bashrc", "../escaped.txt") 4. User accepts the transfer and selects a download directory 5. File is written outside the selected directory, potentially overwriting sensitive files Affected components: - "src/app/server/zmodem.js" - "prepareReceiveFile()" at line 736 - "src/app/server/trzsz.js" - "getUniqueFilePath()" at line 559, "openSaveFile()" callback, and "savedFilePaths" mapping Patches - https://github.com/electerm/electerm/commit/fde153d677a170c5816368f6586647f3af4ef284 Workarounds If upgrading is not immediately possible, users can mitigate this vulnerability by: 1. Only connecting to trusted SSH servers 2. Rejecting or canceling any incoming Zmodem or Trzsz file transfers from untrusted sources 3. Avoiding the use of Zmodem ("sz"/"rz") and Trzsz ("trz"/"tsz") commands on untrusted servers
Affected Packages
https://github.com/electerm/electerm.git (GITHUB):
Affected version(s) >=v0.0.1 <v3.11.11Fix Suggestion:
Update to version v3.11.11electerm (NPM):
Affected version(s) >=0.1.0 <3.11.11Fix Suggestion:
Update to version 3.11.11Related Resources (3)
Do you need more information?
Contact UsCVSS v4
Base Score:
7.1
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
HIGH
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.1
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
LOW
Weakness Type (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')