CVE-2026-88514
- EPSS 0.1%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 07.10.2026 21:17:21
An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information.
CVE-2026-41253
- EPSS 0.2%
- Veröffentlicht 18.04.2026 05:27:08
- Zuletzt bearbeitet 18.05.2026 16:50:19
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname with an initia...
CVE-2025-22275
- EPSS 0.51%
- Veröffentlicht 03.01.2025 05:15:08
- Zuletzt bearbeitet 20.06.2025 18:10:51
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remot...
CVE-2024-38396
- EPSS 1.7%
- Veröffentlicht 16.06.2024 21:15:50
- Zuletzt bearbeitet 20.06.2025 18:05:57
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the ...
CVE-2024-38395
- EPSS 1.5%
- Veröffentlicht 16.06.2024 01:15:48
- Zuletzt bearbeitet 18.06.2025 16:40:48
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."
CVE-2023-46321
- EPSS 0.66%
- Veröffentlicht 23.10.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:28:17
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
CVE-2023-46322
- EPSS 0.66%
- Veröffentlicht 23.10.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:28:18
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period...
CVE-2023-46300
- EPSS 1.18%
- Veröffentlicht 22.10.2023 04:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:15
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.
CVE-2023-46301
- EPSS 1.18%
- Veröffentlicht 22.10.2023 04:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:15
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.
CVE-2022-45872
- EPSS 0.88%
- Veröffentlicht 23.11.2022 22:15:09
- Zuletzt bearbeitet 25.04.2025 19:15:48
iTerm2 before 3.4.18 mishandles a DECRQSS response.