Vulnerability CVE-2024-38395


Published: 2024-06-16

Description:
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

 References:
https://iterm2.com/downloads.html
https://gitlab.com/gnachman/iterm2/-/commit/f1e89f78dd72dcac3ba66d3d6f93db3f7f649219
https://www.openwall.com/lists/oss-security/2024/06/15/1
https://gitlab.com/gnachman/iterm2/-/tags/v3.5.2

Copyright 2026, cxsecurity.com

 

Back to Top