CRITICAL🇵🇱 Wersja polska

CVE-2025-22275

CVSS 9.3v3.1pub. 2025-01-03upd. 2025-06-20

iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.

🤖 AI Analysis
How it works

In specific SSH Integration and it2ssh configurations, the iTerm2 application writes data from terminal sessions to the /tmp/framer.txt file on a remote host. This file can contain sensitive data — including commands executed in the terminal — and is potentially accessible to other users of the system or processes on that host. The vulnerability is exposed during remote SSH logins to hosts with a standard Python installation, which is required for the integration mechanism to function.

Impact

An attacker or other unauthorized user on a remote host can read the contents of the /tmp/framer.txt file and gain access to sensitive information from terminal sessions, such as executed commands that may potentially contain passwords, tokens, or other authentication data.

Mitigation & patch

Update iTerm2 to version 3.5.11 or later, in which the issue has been fixed. Details of the fix are available in the vendor's changelog at the address provided in the references.

Who is affected

iTerm2 in versions 3.5.6 to 3.5.10 (prior to 3.5.11), with active it2ssh or SSH Integration configuration, during connections to hosts with Python installed.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Iterm2

    APP
    Iterm2
    3.5.6 – 3.5.11 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38395CRITICAL9.8PL ✓same product

iTerm2: RCE przez niezastosowanie ustawienia tytułu okna terminala

CVE-2024-38396CRITICAL9.8PL ✓same product

iTerm2: wstrzyknięcie kodu przez sekwencję escape w integracji tmux (RCE)

CVE-2023-46321CRITICAL9.8PL ✓same product

iTerm2: brak sanityzacji ścieżek w URL-ach x-man-page umożliwia wstrzyknięcie poleceń

CVE-2023-46322CRITICAL9.8PL ✓same product

iTerm2: brak sanityzacji nazwy hosta SSH w URL przed wersją 3.5.0beta12

CVE-2023-46300CRITICAL9.8PL ✓same product

RCE w iTerm2 przez nieprawidłową obsługę sekwencji escape w integracji tmux