CVE-2025-22275CRITICAL 9.3EPSS p38.2%
CVE-2025-22275CVE-2025-22275
Description
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
Scoring
| CVSS 3.1 | 9.3 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
| EPSS | 0.49% probability of exploitation · percentile 38.2% · 2026-06-18T12:00:27Z |
| Published | 2025-01-03 |
| Last modified | 2025-06-20 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Insertion of Sensitive Information into Log Filecwe-532 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.