CVE-2026-41253Disclosure(iterm2 / iterm2)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch iterm2 iterm2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname with an initial ace/c+ substring, aka "hypothetical in-band signaling abuse." This occurs because iTerm2 accepts the SSH conductor protocol from terminal output that does not originate from a legitimate conductor session.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iterm2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
iterm2

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-18: 2Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-18: 204-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • SecureChap@SecureChap
    Disclosure

    cat readme.txt That simple command in iTerm2 triggered local code execution on macOS systems. The vulnerability, dubbed MAD Bugs (CVE-2026-41253), stems from a trust failure: iTerm2 treats untrusted terminal output as valid SSH conductor protocol messages. An attacker crafts a malicious file that, when displayed, forges a DCS 2000p hook sequence to simulate announcing a conductor session. It then sends forged OSC 135 replies mimicking protocol handshakes: begin <id>, end <id> <status> r, and unhook. iTerm2 responds by issuing getshell() and pythonversion() requests; the forged replies push its state machine forward. With the session established, iTerm2 builds a run command embedding a base64-encoded payload and pipes it to the PTY. No actual SSH conductor runs - the local shell ingests those base64 chunks directly as input. The payload's final 128-byte chunk reads ace/c+aliFIo: decodes cleanly as base64 while doubling as an executable relative path. Attackers can shape the sshargs in the initial hook, embedding them into the run command's base64 for targeted control. Reported March 30, 2026, and fixed the next day in commit a9e745993c. Public disclosure came April 17, 2026. Found by an AI through an OpenAI collaboration with the MAD project. The fix had not yet landed in stable releases at disclosure. A terminal emulator tricked by its own output became the vector for shell access.

    Post summary

    The text announces a newly disclosed macOS vulnerability (CVE‑2026‑41253) in iTerm2, explains the exploitation method in detail, and notes that a patch was added shortly after discovery.

    0000058
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41253 In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name… https://www.cve.org/CVERecord?id=CVE-2026-41253

    Post summary

    CVE-2026-41253 is a code execution vulnerability in iTerm2 3.6.9 where displaying a .txt file can trigger malicious execution via specific control sequences, with details linked to its CVE record.

    0000055
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiterm2iterm2---

Explore more