iTerm2 is a widely used terminal emulator for macOS that provides developers with advanced session management and scripting capabilities. Vulnerabilities affecting the product skew strongly toward critical-severity outcomes and concentrate across input-handling and information-disclosure weakness classes—including code injection, output neutralization failures, and sensitive-information exposure—that are characteristic of a complex, interactive application processing untrusted terminal content and user-controlled sequences. Defenders should prioritize updates to this vendor given the severity profile and the prominence of iTerm2 in development environments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iterm2 over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9535CRITICAL A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the te | Oct 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2024-38396CRITICAL An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enab | Jun 16, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-38395CRITICAL In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable." | Jun 16, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-46301CRITICAL iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload. | Oct 22, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-22275CRITICAL iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occ | Jan 3, 2025 | 9.3 | 29 | NO | NO |
CVE-2023-46322CRITICAL iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characte | Oct 23, 2023 | 9.8 | 27 | NO | NO |
CVE-2026-41253HIGH In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid outp | Apr 18, 2026 | 7.8 | 25 | NO | NO |
CVE-2023-46321CRITICAL iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line. | Oct 23, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-46300CRITICAL iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration. | Oct 22, 2023 | 9.8 | 24 | NO | NO |
CVE-2022-45872CRITICAL iTerm2 before 3.4.18 mishandles a DECRQSS response. | Nov 23, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iterm2.
Media articles that mention a CVE ID that affects a product developed by Iterm2 — matched by CVE ID, not by vendor name.