CVE-2024-38396: ITERM2
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.
Affected products
- ITERM2 ITERM2: from 3.5.0, before 3.5.2 (fixed in 3.5.2)
Published 2024-06-16. Last modified 2026-06-17.