CVE-2026-41253
6.9 MEDIUMIn iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contain...
Published: 2026-04-18 · Last updated: 2026-05-18
Severity and scoring
- CVSS
- 6.9 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
- CWE
- CWE-829
Affected products
| Vendor | Product |
|---|---|
| iterm2 | iterm2 |
Description
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname with an initial ace/c+ substring, aka "hypothetical in-band signaling abuse." This occurs because iTerm2 accepts the SSH conductor protocol from terminal output that does not originate from a legitimate conductor session.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-41253
- [Exploit reference]https://blog.calif.io/p/mad-bugs-even-cat-readmetxt-is-not
- [Patch]https://github.com/gnachman/iTerm2/commit/a9e745993c2e2cbb30b884a16617cd5495899f86
- [Other]https://iterm2.com/downloads.html
- [Other]https://news.ycombinator.com/item?id=47809190
Related CVEs
Same CWE
- CVE-2026-42089 — Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved (8.6 HIGH)
- CVE-2026-48124 — Cursor is a code editor built for programming with AI
- CVE-2026-12057 — When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfac... (8.6 HIGH)
- CVE-2026-53810 — OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading towar... (8.8 HIGH)
- CVE-2026-52858 — Vim is an open source, command line text editor (7.8 HIGH)