CVE-2024-38396: ITERM2

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

Affected products

  • ITERM2 ITERM2: from 3.5.0, before 3.5.2 (fixed in 3.5.2)

Published 2024-06-16. Last modified 2026-06-17.