CVE-2023-46300: ITERM2

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

Affected products

  • ITERM2 ITERM2: before 3.4.20 (fixed in 3.4.20)

Published 2023-10-22. Last modified 2026-06-17.