GHSA-g29v-q6h7-76whMedium
electerm's encrypt method not safe enough
🔗 CVE IDs covered (1)
📋 Description
Impact
Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks.
Patches
- https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937
Workarounds
- No
References
- Report / credit: https://github.com/Curly-Haired-Baboon
- Electerm releases: https://github.com/electerm/electerm/releases
🎯 Affected products1
- npm/electerm:< 3.9.5
🔗 References (5)
- https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh
- https://github.com/electerm/electerm/releases/tag/v3.9.5
- https://nvd.nist.gov/vuln/detail/CVE-2026-45787
- https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937
- https://github.com/advisories/GHSA-g29v-q6h7-76wh