CVE-2025-22275: Critical severity iterm2 vulnerability
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22275?
CVE-2025-22275 has been classified with a medium severity level due to the potential exposure of sensitive information.
How do I fix CVE-2025-22275?
To fix CVE-2025-22275, users should upgrade to iTerm2 version 3.5.11 or later.
What versions of iTerm2 are affected by CVE-2025-22275?
iTerm2 versions 3.5.6 through 3.5.10 are affected by CVE-2025-22275.
Who is affected by CVE-2025-22275?
Users of iTerm2 who utilize certain it2ssh and SSH Integration configurations during remote logins may be affected by CVE-2025-22275.
What type of information can be leaked due to CVE-2025-22275?
CVE-2025-22275 allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file.