Skip to content

electerm

v3.15.120 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 15d CLI & Terminal
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

ai android electerm electron file-manager ftp
+13 more
linux-app macos-app mcp rdp serialport sftp spice ssh telnet cli vnc windows-app zmodem

Affected surfaces

rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 11d

The v3.15.120 release of electerm fixes multiple unsafe file name parsing vulnerabilities affecting custom editor handling, FTP/SFTP transfers, folder‑size checks, and RDP file transfer operations.

Why it matters: All four security fixes (severity 90) eliminate exploitable parsing flaws across core data‑transfer surfaces; operators should upgrade immediately to prevent arbitrary path manipulation attacks.

Summary

AI summary

Updates New features/UI/Updates, 新功能/界面/更新, and Security fixes across a mixed release.

Changes in this release

Security Critical

Fixes unsafe file name parsing in custom editor handling

Fixes unsafe file name parsing in custom editor handling

Source: llm_adapter@2026-07-15

Confidence: high

Security Critical

Fixes unsafe file name parsing during FTP/SFTP transfers

Fixes unsafe file name parsing during FTP/SFTP transfers

Source: llm_adapter@2026-07-15

Confidence: high

Security Critical

Fixes unsafe file name parsing when checking folder size

Fixes unsafe file name parsing when checking folder size

Source: llm_adapter@2026-07-15

Confidence: high

Security Critical

Fixes unsafe file name parsing in RDP file transfer

Fixes unsafe file name parsing in RDP file transfer

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds compare option to context menu when selecting two files with same extension

Adds compare option to context menu when selecting two files with same extension

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Saves split view state to workspace data (issue #4418)

Saves split view state to workspace data (issue #4418)

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds flashing effect to add/save button for SSH tunnel/connection hopping edit

Adds flashing effect to add/save button for SSH tunnel/connection hopping edit

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Improves multi‑file transfer context menu text

Improves multi‑file transfer context menu text

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Adds wiki link for custom CSS documentation

Adds wiki link for custom CSS documentation

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Removes trailing slash from SFTP address to avoid issues

Removes trailing slash from SFTP address to avoid issues

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

New features/UI/Updates

  • When selecting two files with the same extension, context menu would have a compare option
  • #4418 Save split view state to workspace data
  • Add flashing effect to add/save button for SSH tunnel/connection hopping edit
  • UX: Improve multi file transfer context menu text
  • Add wiki link for custom CSS

Security fixes

  • Parse unsafe file name when edit with custom editor
  • Parse unsafe file name when FTP/SFTP transfer
  • Parse unsafe file name when check folder size
  • Fix RDP file transfer unsafe file name issue

Bug fixes

  • Remove trailing slash in SFTP address to avoid issue

新功能/界面/更新

  • 当选择两个相同扩展名的文件时,右键菜单会显示比较选项
  • #4418 将分屏视图状态保存到工作区数据
  • 为 SSH 隧道/连接跳转编辑的添加/保存按钮添加闪烁效果
  • 体验优化:改进多文件传输右键菜单文案
  • 添加自定义 CSS 的 wiki 链接

安全修复

  • 编辑自定义编辑器时解析不安全的文件名
  • FTP/SFTP 传输时解析不安全的文件名
  • 检查文件夹大小时解析不安全的文件名
  • 修复 RDP 文件传输中不安全文件名的问题

问题修复

  • 移除 SFTP 地址中的尾部斜杠以避免问题

Download下载: https://electerm.org

Security Fixes

  • Parse unsafe file name when editing with a custom editor
  • Parse unsafe file name during FTP/SFTP transfer
  • Parse unsafe file name when checking folder size
  • Fix RDP file transfer unsafe file name issue

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track electerm

Get notified when new releases ship.

Sign up free

About electerm

Terminal/ssh/sftp/ftp/telnet/serialport/RDP/VNC/Spice client(linux, mac, win)

All releases →

Related context

Earlier breaking changes

  • v3.11.0 Deprecates permissive CORS on MCP server; adds optional API key authentication.

Beta — feedback welcome: [email protected]