CVE-2026-49255: electerm has Command Injection in File System Operations (rmrf, mv, cp)
A command injection vulnerability exists in electerm’s file system operations (rmrf, mv, cp) in src/app/lib/fs.js. These functions construct shell commands by interpolating file paths directly into command strings without escaping shell metacharacters.
Vulnerable functions:
rmrf()- Usesrm -rf "${path}"(double quotes, vulnerable to"injection)mv()- Usesmv '${from}' '${to}'(single quotes, vulnerable to'injection)cp()- Usescp -r "${from}" "${to}"(double quotes, vulnerable to"injection)
Attack scenario:
- Attacker controls a malicious SSH/SFTP server
- Server lists files with shell metacharacters in names (e.g.,
file"$(touch /tmp/pwned)") - Victim connects to the server and performs file operations (remote-to-local transfer, rename on conflict, etc.)
- The malicious filename is passed to
rmrf(),mv(), orcp()without sanitization - Shell metacharacters break out of the quoted argument and execute arbitrary commands
Impact includes:
- Arbitrary command execution as the electerm desktop user
- Data exfiltration, malware installation, or system compromise
- Both POSIX (bash) and Windows (PowerShell) platforms are affected
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49255 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →