OVERVIEW CVE-2026-41253 affects iTerm2 versions through 3.6.9 and involves improper handling of terminal control sequences (DCS 2000p and OSC 135 data). The vulnerability allows arbitrary code execution when displaying .txt files if the working directory contains a specially crafted filename that mimics legitimate conductor encoding output. The flaw stems from iTerm2's acceptance of SSH conductor protocol directives from untrusted terminal output, rather than only from authenticated conductor sessions. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.9 (MEDIUM) with a local attack vector, high complexity requirement, and no privilege escalation needed. The attack requires user interaction (displaying a file) and delivers high impact to confidentiality and integrity, plus low availability impact. The attack surface is limited to systems where users open .txt files in directories containing attacker-controlled filenames, which explains the high complexity rating. The low EPSS score (0.00005) suggests minimal real-world prevalence compared to other CVEs. EXPLOITATION STATUS There is no current evidence of active exploitation, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and its inactive Hot List status. No public exploit code availability is documented. The specialized nature of the attack—requiring both a malicious filename and user interaction—combined with the low EPSS score suggests limited community attention and exploitation likelihood in operational environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 3.6.9CPE match | cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* | ||
<= 3.6.9CPE matchmatch criteria | cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.