iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.
[
{
"digest": {
"line_hashes": [
"190271808016798993621080830245235782327",
"121735224976567983453209453020234181638",
"273038938875908312311681729084193125914",
"106630090295476597812726766506075364930"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2023-46300-e06130ea",
"target": {
"file": "sources/TmuxController.h"
},
"source": "https://github.com/gnachman/iterm2/commit/ae8192522661c34d1cbe57f6f9ef2ff0a337c2a5"
}
]