CVE-2024-38395: ITERM2

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

Affected products

  • ITERM2 ITERM2: from 3.5.0, before 3.5.2 (fixed in 3.5.2)

Published 2024-06-16. Last modified 2026-06-17.