This release includes 4 security fixes for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
ReleasePort's take
Moderate signalThe v3.15.120 release of electerm fixes multiple unsafe file name parsing vulnerabilities affecting custom editor handling, FTP/SFTP transfers, folder‑size checks, and RDP file transfer operations.
Why it matters: All four security fixes (severity 90) eliminate exploitable parsing flaws across core data‑transfer surfaces; operators should upgrade immediately to prevent arbitrary path manipulation attacks.
Summary
AI summaryUpdates New features/UI/Updates, 新功能/界面/更新, and Security fixes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes unsafe file name parsing in custom editor handling Fixes unsafe file name parsing in custom editor handling Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Fixes unsafe file name parsing during FTP/SFTP transfers Fixes unsafe file name parsing during FTP/SFTP transfers Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Fixes unsafe file name parsing when checking folder size Fixes unsafe file name parsing when checking folder size Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Security | Critical |
Fixes unsafe file name parsing in RDP file transfer Fixes unsafe file name parsing in RDP file transfer Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds compare option to context menu when selecting two files with same extension Adds compare option to context menu when selecting two files with same extension Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Saves split view state to workspace data (issue #4418) Saves split view state to workspace data (issue #4418) Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds flashing effect to add/save button for SSH tunnel/connection hopping edit Adds flashing effect to add/save button for SSH tunnel/connection hopping edit Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Improves multi‑file transfer context menu text Improves multi‑file transfer context menu text Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds wiki link for custom CSS documentation Adds wiki link for custom CSS documentation Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Removes trailing slash from SFTP address to avoid issues Removes trailing slash from SFTP address to avoid issues Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
New features/UI/Updates
- When selecting two files with the same extension, context menu would have a compare option
- #4418 Save split view state to workspace data
- Add flashing effect to add/save button for SSH tunnel/connection hopping edit
- UX: Improve multi file transfer context menu text
- Add wiki link for custom CSS
Security fixes
- Parse unsafe file name when edit with custom editor
- Parse unsafe file name when FTP/SFTP transfer
- Parse unsafe file name when check folder size
- Fix RDP file transfer unsafe file name issue
Bug fixes
- Remove trailing slash in SFTP address to avoid issue
新功能/界面/更新
- 当选择两个相同扩展名的文件时,右键菜单会显示比较选项
- #4418 将分屏视图状态保存到工作区数据
- 为 SSH 隧道/连接跳转编辑的添加/保存按钮添加闪烁效果
- 体验优化:改进多文件传输右键菜单文案
- 添加自定义 CSS 的 wiki 链接
安全修复
- 编辑自定义编辑器时解析不安全的文件名
- FTP/SFTP 传输时解析不安全的文件名
- 检查文件夹大小时解析不安全的文件名
- 修复 RDP 文件传输中不安全文件名的问题
问题修复
- 移除 SFTP 地址中的尾部斜杠以避免问题
Download下载: https://electerm.org
Security Fixes
- Parse unsafe file name when editing with a custom editor
- Parse unsafe file name during FTP/SFTP transfer
- Parse unsafe file name when checking folder size
- Fix RDP file transfer unsafe file name issue
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About electerm
Terminal/ssh/sftp/ftp/telnet/serialport/RDP/VNC/Spice client(linux, mac, win)
Beta — feedback welcome: [email protected]