CVE-2019-9535General(iterm2 / iterm2)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an attacker to execute arbitrary commands on their victim's computer by providing malicious output to the terminal. It could be exploited using command-line utilities that print attacker-controlled content.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iterm2

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
iterm2

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-26: 1Technical Details · 2026-05-26: 105-26
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Technology Interpreters, Inc.@TechTranslators
    General

    This isn't unique to Kitty. iTerm2's CVE-2019-9535 was a famous escape-sequence RCE. VTE, xterm, and tmux have all shipped parser bugs. Escape sequences are a 1970s spec that grew new features for 50 years — the attack surface keeps growing.

    Post summary

    The post highlights that iTerm2’s CVE‑2019‑9535 was an escape‑sequence RCE and that VTE, xterm, and tmux have similar parser bugs, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    1000036
    35 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiterm2iterm2---

Explore more