electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L상세 설명
Impact
A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.
A malicious SSH server or remote shell process can send a specially crafted filename such as ../escaped.txt to escape the user-selected download directory and write files to arbitrary locations on the user's filesystem, subject to process permissions.
Attack scenario:
- User connects to a malicious SSH server
- Attacker initiates a Zmodem or Trzsz file transfer
- Attacker supplies a traversal filename (e.g.,
../../.bashrc,../escaped.txt) - User accepts the transfer and selects a download directory
- File is written outside the selected directory, potentially overwriting sensitive files
Affected components:
src/app/server/zmodem.js-prepareReceiveFile()at line 736src/app/server/trzsz.js-getUniqueFilePath()at line 559,openSaveFile()callback, andsavedFilePathsmapping
Patches
Workarounds
If upgrading is not immediately possible, users can mitigate this vulnerability by:
- Only connecting to trusted SSH servers
- Rejecting or canceling any incoming Zmodem or Trzsz file transfers from untrusted sources
- Avoiding the use of Zmodem (
sz/rz) and Trzsz (trz/tsz) commands on untrusted servers
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.