CVSS 3.1 Score 9.8 of 10 (high)


Published Oct 23, 2023
Updated: Nov 1, 2023


CVE-2023-46322 is a critical cyber vulnerability that affects iTerm2 before version 3.5.0beta12. This vulnerability arises from a lack of sanitization of ssh hostnames in URLs in the iTermSessionLauncher.m file. It allows for non-alphanumeric initial characters and the presence of characters outside the set of alphanumeric characters, dash, and period in hostnames. The potential danger to organizations is high, with a base severity rating of CRITICAL and a base score of 9.8 according to The vulnerability has an impact on integrity and confidentiality, with an availability impact that is also high. The exploitability score is 3.9, indicating that it can be exploited relatively easily. To remediate this vulnerability, organizations should update their iTerm2 software to version 3.5.0beta12 or later versions as they become available.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-46322 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options