CVE-2025-22275·Python vulnerability
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote logins to hosts that have a common Python installation.
- Severity
- critical
- Software
- Python
- Fixed in
- 3.5.11
- Published
- 2025-01-03
Affected versions
From: 3.5.6
Until: 3.5.11
Fixed in: 3.5.11
How to fix this CVE
Update Python to version 3.5.11 or later to patch the temporary file information disclosure vulnerability. Organizations using iTerm2 with SSH integration should prioritize this update to prevent unauthorized access to sensitive terminal command data stored in world-readable temporary files. Ensure all systems with Python installed apply this patch as soon as possible.
sudo dnf update python3Defensia detects this vulnerability
How to check if you are affected
- Step 1: Check installed Python version with 'python3 --version' and verify it is 3.5.11 or newer
- Step 2: Examine iTerm2 SSH integration configuration files typically located in ~/.ssh/config and look for it2ssh or SSH Integration directives
- Step 3: Search system logs and audit trails for unauthorized access attempts to /tmp/framer.txt using 'grep -r framer.txt /var/log/'
- Step 4: Run 'python3 --version' again post-update to confirm the patched version is active, then restart any SSH sessions
FAQ
What is CVE-2025-22275?
CVE-2025-22275 is a critical information disclosure vulnerability in Python versions 3.5.6 through 3.5.10 that allows remote attackers to access sensitive terminal command data through an insufficiently protected temporary file during SSH integration operations. The vulnerability affects systems using iTerm2 with SSH forwarding enabled.
Is CVE-2025-22275 being actively exploited?
No, CVE-2025-22275 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the vulnerability has a critical CVSS score of 9.3 and should be treated with high priority.
What versions of Python are affected by CVE-2025-22275?
Python versions 3.5.6 through 3.5.10 are vulnerable. The vulnerability was patched in Python 3.5.11 and later releases.
How do I check if my server is vulnerable to CVE-2025-22275?
Run 'python3 --version' to check your installed version. If the output shows version 3.5.6 through 3.5.10, your system is vulnerable and requires immediate patching to 3.5.11 or newer.
Does Defensia detect CVE-2025-22275?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Python is installed on a monitored server, CVE-2025-22275 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-22275. Free for 1 server.
Get started free