GHSA-g29v-q6h7-76wh
electerm's encrypt method not safe enough
Quick fix
GHSA-g29v-q6h7-76wh — electerm: upgrade to the fixed version with the command below.
npm install electerm@3.9.5Details
### Impact _Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks._
### Patches
- https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937
### Workarounds
- No
### References - Report / credit: https://github.com/Curly-Haired-Baboon - Electerm releases: https://github.com/electerm/electerm/releases
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/electerm/electerm/security/advisories/GHSA-g29v-q6h7-76wh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45787[ADVISORY]
- https://github.com/electerm/electerm/commit/9dd8295e37d53396b980cd45dfc5ed11ad79b937[WEB]
- https://github.com/electerm/electerm[PACKAGE]
- https://github.com/electerm/electerm/releases/tag/v3.9.5[WEB]