CVE-2026-41253: High severity iTerm2 iTerm2 vulnerability
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname with an initial ace/c+ substring, aka "hypothetical in-band signaling abuse." This occurs because iTerm2 accepts the SSH conductor protocol from terminal output that does not originate from a legitimate conductor session.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41253?
CVE-2026-41253 is rated as a high-severity vulnerability due to its potential for code execution.
How do I fix CVE-2026-41253?
To fix CVE-2026-41253, upgrade iTerm2 to version 3.6.10 or later.
How does CVE-2026-41253 allow for code execution?
CVE-2026-41253 allows code execution when displaying a malicious .txt file in specific working directory conditions.
What versions of iTerm2 are affected by CVE-2026-41253?
CVE-2026-41253 affects iTerm2 versions up to and including 3.6.9.
Can CVE-2026-41253 impact users on older operating systems?
Yes, users on older operating systems using vulnerable versions of iTerm2 are at risk from CVE-2026-41253.