Electerm fixed a high-severity command injection vulnerability tracked as CVE-2026-73224 that could let a malicious FTP or SFTP server execute arbitrary commands on a user's system. The flaw affected versions prior to 3.15.120 and was triggered when a user downloaded a crafted folder and then opened Properties and used Calculate Size. According to the advisory, the application passed a server-controlled folder name into a shell command used to run du -sh without properly escaping single quotes, creating a CWE-78 command injection condition.
The issue was addressed in Electerm v3.15.120, whose release notes describe multiple security fixes for unsafe file-name parsing across custom editor actions, FTP/SFTP transfers, folder size checks, and RDP file transfer workflows. The vulnerability carries a CVSS 3.1 rating of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating high impact to confidentiality, integrity, and availability, and users are advised to upgrade to the patched release.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-73224 was newly received by security-advisories@github.com. The vulnerability describes a command injection flaw in Electerm's folder size calculation that can let a malicious FTP or SFTP server execute arbitrary commands after user interaction.
Electerm released version 3.15.120, which included multiple security fixes for unsafe file name parsing, including the folder size check workflow affected by CVE-2026-73224. The release notes also mention fixes for custom editor operations, FTP/SFTP transfers, and RDP file transfer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.