CVE-2019-9535CWE-349

CVE-2019-9535: vulnerability in iTerm2

iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution

Published · Updated

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.5%
exploitation probability
2.5%top 16% of all CVEs
observed exploitation
nono source reports it
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an attacker to execute arbitrary commands on their victim's computer by providing malicious output to the terminal. It could be exploited using command-line utilities that print attacker-controlled content.
Affected products
iTerm2 · iTerm2
Related CVEs — iTerm2

In the same product, most dangerous first.