PT-2024-27979 · Iterm2 · Iterm2

·

CVE-2024-38395

·

Published

2024-06-16

·

Updated

2025-06-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iTerm2 versions prior to 3.5.2
Description The issue arises because the "Terminal may report window title" setting is not honored, potentially leading to remote code execution, although it is noted that exploitation is not trivial.
Recommendations For versions prior to 3.5.2, update to version 3.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the "Terminal may report window title" setting until a patch is available.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38395

Affected Products

Iterm2