If you properly set up your ssh client (No agent forwarding or X11 forwarding)

Terminal, too; some escape sequences are able to perform attacks in old or buggy terminal emulators.

Even newer ones. Iterm2 had CVE-2026-41253 recently. Or things like Tmux.

Yes, I was thinking of iTerm2. "Older" means not the latest release and "buggy" includes well-intentioned vulnerabilities.

Sure. 3.6.9 (which was affected) was the most recent iTerm2 when that CVE came out.

Hence "or"