electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling
A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Trzsz protocols, electerm uses the remote-supplied filename directly in path.join() with the user-selected download directory without sanitization.
A malicious SSH server or remote shell process can send a specially crafted filename such as ../escaped.txt to escape the user-selected download directory and write files to arbitrary locations on the user's filesystem, subject to process permissions.
Attack scenario:
../../.bashrc, ../escaped.txt)Affected components:
src/app/server/zmodem.js - prepareReceiveFile() at line 736src/app/server/trzsz.js - getUniqueFilePath() at line 559, openSaveFile() callback, and savedFilePaths mappingIf upgrading is not immediately possible, users can mitigate this vulnerability by:
sz/rz) and Trzsz (trz/tsz) commands on untrusted servers왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 71.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 71.00 |
VPI 공식 vpi-v1 기준