CVE-2024-38396
CRITICALiTerm2 <3.5.2 - Code Injection
Title source: llmDescription
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.1055
EPSS Percentile
93.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
iterm2/iterm2
3.5.0 - 3.5.2
Published
Jun 16, 2024
Tracked Since
Feb 18, 2026