logo

iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution

ID: 40972ce0-b00c-5233-8689-334cf8e4ffbf

STIX ID: report--40972ce0-b00c-5233-8689-334cf8e4ffbf

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Abinaya

...
...

Researchers disclosed a critical iTerm2 vulnerability in the SSH integration where malicious terminal escape sequences (DCS 2000p and OSC 135) can impersonate the SSH conductor; simply viewing crafted text or connecting to a hostile SSH server can cause iTerm2 to treat attacker-supplied responses as legitimate and lead to local execution of attacker-controlled commands. A fix was committed by iTerm2 shortly after disclosure but had not reached stable releases, so users are advised to avoid untrusted text files and unknown SSH servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.