Vulnerability Description
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iterm2 | Iterm2 | >= 3.5.6, < 3.5.11 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gnachman/iterm2/-/wikis/SSH-Integration-Information-LeakThird Party Advisory
- https://iterm2.com/downloads/stable/iTerm2-3_5_11.changelogRelease Notes
- https://news.ycombinator.com/item?id=42579472Issue Tracking
FAQ
What is CVE-2025-22275?
CVE-2025-22275 is a vulnerability with a CVSS score of 9.3 (CRITICAL). iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ss...
How severe is CVE-2025-22275?
CVE-2025-22275 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-22275?
Check the references section above for vendor advisories and patch information. Affected products include: Iterm2 Iterm2.