{"id":"CVE-2025-22275","details":"iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.","modified":"2026-08-12T03:51:27.198822036Z","published":"2025-01-03T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22275.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.5.6"},{"fixed":"3.5.11"}],"source":"AFFECTED_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"introduced":"3.5.6"},{"fixed":"3.5.11"}]},{"source":"DESCRIPTION","extracted_events":[{"introduced":"3.5.6"},{"fixed":"3.5.10"},{"fixed":"3.5.11"}]}],"cna_assigner":"mitre","cwe_ids":["CWE-532"]},"references":[{"type":"WEB","url":"https://gitlab.com/gnachman/iterm2/-/wikis/SSH-Integration-Information-Leak"},{"type":"WEB","url":"https://iterm2.com/downloads/stable/iTerm2-3_5_11.changelog"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=42579472"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22275.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22275"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnachman/iterm2","events":[{"introduced":"6604bc0843e66549475291428c14124c6c3fee9b"},{"fixed":"80c262998f2503618cadfc32dbebc01c4fb985bb"}],"database_specific":{"extracted_events":[{"introduced":"3.5.6"},{"fixed":"3.5.11"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:iterm2:iterm2:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22275.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}]}