PT-2025-4405 · Iterm2 · Iterm2

Kwpolska

·

Published

2025-01-03

·

Updated

2026-04-20

·

CVE-2025-22275

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions iTerm2 versions 3.5.6 through 3.5.10
Description The issue sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
Recommendations For iTerm2 versions 3.5.6 through 3.5.10, update to version 3.5.11 to resolve the issue. As a temporary workaround, consider restricting access to the /tmp/framer.txt file to minimize the risk of exploitation. Avoid using certain it2ssh and SSH Integration configurations that may be vulnerable until the issue is resolved.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-22275

Affected Products

Iterm2