CVE-2026-73225: electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recursive transfers in src/client/components/file-transfer/transfer.jsx pass server-supplied file.name and folder.name values to resolve without sanitization. This issue is fixed in version 3.15.120.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
electermto a version that resolves this vulnerability.Fixed in 3.15.120
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73225?
The severity of CVE-2026-73225 is rated as high with a score of 8.1.
How do I fix CVE-2026-73225?
To fix CVE-2026-73225, upgrade Electerm to version 3.15.120 or later.
What type of vulnerability is CVE-2026-73225?
CVE-2026-73225 is classified as a path traversal vulnerability.
What impact does CVE-2026-73225 have on users?
CVE-2026-73225 allows a malicious FTP or SFTP server to write files outside the intended download directory, potentially leading to unauthorized access to sensitive data.
Which versions of Electerm are affected by CVE-2026-73225?
Electerm versions prior to 3.15.120 are affected by CVE-2026-73225.