CVE-2025-22275

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
03/01/2025
Last modified:
20/06/2025

Description

iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:* 3.5.6 (including) 3.5.11 (excluding)