PT-2024-27979 · Iterm2 · Iterm2

David Leadbeater

·

Published

2024-06-16

·

Updated

2025-06-18

·

CVE-2024-38395

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iTerm2 versions prior to 3.5.2
Description The issue arises because the "Terminal may report window title" setting is not honored, potentially leading to remote code execution, although it is noted that exploitation is not trivial.
Recommendations For versions prior to 3.5.2, update to version 3.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the "Terminal may report window title" setting until a patch is available.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-38395

Affected Products

Iterm2