[GH-ISSUE #3865] Command Injection #2661

Closed
opened 2026-02-27 00:53:47 +03:00 by kerem · 1 comment
Owner

Originally created by @d0ge on GitHub (Mar 21, 2025).
Original GitHub issue: https://github.com/electerm/electerm/issues/3865

Electerm Version and download file extension(Electerm版本和下载文件后缀)

electerm-xx.xx.xx-mac-arm64.dmg

Platform detail (平台详情)

mac ARM

What steps will reproduce the bug?(重新问题的详细步骤)

Dear Electerm team,

I could not find any published security guidance or responsible disclosure process on your website or GitHub, so I am opening this issue to bring attention to a potential concern.

Command Injection

I have reason to believe there may be a command injection vulnerability present. Due to the sensitive nature of security issues, I would prefer to share specific details privately, in line with responsible disclosure practices.

Could you please advise on the appropriate channel (email or otherwise) to securely disclose this information?

Thank you for your work on Electerm — looking forward to your response.

WoW

What should have happened?(期望的结果)

Escape user data

Would this happen in other terminal app(是否能够在其他同类软件重现这个问题)

Yes %)

Additional information(其他任何相关信息)

No response

Originally created by @d0ge on GitHub (Mar 21, 2025). Original GitHub issue: https://github.com/electerm/electerm/issues/3865 ### Electerm Version and download file extension(Electerm版本和下载文件后缀) electerm-xx.xx.xx-mac-arm64.dmg ### Platform detail (平台详情) mac ARM ### What steps will reproduce the bug?(重新问题的详细步骤) Dear Electerm team, I could not find any published security guidance or responsible disclosure process on your website or GitHub, so I am opening this issue to bring attention to a potential concern. Command Injection I have reason to believe there may be a command injection vulnerability present. Due to the sensitive nature of security issues, I would prefer to share specific details privately, in line with responsible disclosure practices. Could you please advise on the appropriate channel (email or otherwise) to securely disclose this information? Thank you for your work on Electerm — looking forward to your response. WoW ### What should have happened?(期望的结果) Escape user data ### Would this happen in other terminal app(是否能够在其他同类软件重现这个问题) Yes %) ### Additional information(其他任何相关信息) _No response_
kerem closed this issue 2026-02-27 00:53:47 +03:00
Author
Owner

@zxdong262 commented on GitHub (Mar 22, 2025):

Thank you for the feedback, please send email to zxdong@gmail.com

<!-- gh-comment-id:2744886043 --> @zxdong262 commented on GitHub (Mar 22, 2025): Thank you for the feedback, please send email to zxdong@gmail.com
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/electerm#2661
No description provided.