logo

iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution

ID: 156e7e9d-ee18-5879-aee9-d9b36f386bfc

STIX ID: report--156e7e9d-ee18-5879-aee9-d9b36f386bfc

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: AnuPriya

...
...

**Executive summary:** A recently disclosed iTerm2 vulnerability allows arbitrary code execution when displaying crafted terminal output (for example, opening a text file). The flaw leverages iTerm2’s SSH integration and special escape sequences (DCS 2000p, OSC 135) to impersonate the remote "conductor" process, trick iTerm2 into sending responses, and cause the local shell to execute attacker-controlled payloads; a commit (a9e74599) fixing the issue was made shortly after disclosure but the patch is not yet in stable public releases, so users should avoid untrusted text and consider disabling SSH integration until updates are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.