CVE-2026-49253: electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling
A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.
A malicious SSH server or remote shell process can send a specially crafted filename such as ../escaped.txt to escape the user-selected download directory and write files to arbitrary locations on the user’s filesystem, subject to process permissions.
Attack scenario:
- User connects to a malicious SSH server
- Attacker initiates a Zmodem or Trzsz file transfer
- Attacker supplies a traversal filename (e.g.,
../../.bashrc,../escaped.txt) - User accepts the transfer and selects a download directory
- File is written outside the selected directory, potentially overwriting sensitive files
Affected components:
src/app/server/zmodem.js-prepareReceiveFile()at line 736src/app/server/trzsz.js-getUniqueFilePath()at line 559,openSaveFile()callback, andsavedFilePathsmapping
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49253 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →