CVE-2026-95835
- EPSS 0.1%
- Veröffentlicht 25.09.2026 16:33:30
- Zuletzt bearbeitet 29.09.2026 21:32:59
Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_remote_askpass()...
CVE-2026-95834
- EPSS 0.13%
- Veröffentlicht 25.09.2026 16:28:09
- Zuletzt bearbeitet 29.09.2026 21:32:59
Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_data() in kit...
- EPSS 0.12%
- Veröffentlicht 25.09.2026 16:22:09
- Zuletzt bearbeitet 29.09.2026 21:32:59
Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never completes the d...
CVE-2026-80431
- EPSS 0.14%
- Veröffentlicht 25.09.2026 13:23:51
- Zuletzt bearbeitet 29.09.2026 21:32:59
Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command() in kitty/s...
CVE-2026-80430
- EPSS 0.16%
- Veröffentlicht 25.09.2026 13:08:13
- Zuletzt bearbeitet 29.09.2026 21:32:59
Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the staging directo...
CVE-2026-95832
- EPSS 0.16%
- Veröffentlicht 25.09.2026 12:54:25
- Zuletzt bearbeitet 29.09.2026 21:32:59
Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in the user's s...
CVE-2026-72913
- EPSS 0.15%
- Veröffentlicht 10.08.2026 21:17:26
- Zuletzt bearbeitet 09.09.2026 20:55:04
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters a...
CVE-2026-54057
- EPSS 0.17%
- Veröffentlicht 12.06.2026 20:07:00
- Zuletzt bearbeitet 16.06.2026 15:42:18
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.
CVE-2026-54056
- EPSS 0.27%
- Veröffentlicht 12.06.2026 20:06:06
- Zuletzt bearbeitet 16.06.2026 15:59:57
Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote `text/uri-list` drops are st...
- EPSS 0.07%
- Veröffentlicht 12.06.2026 20:03:17
- Zuletzt bearbeitet 16.06.2026 16:02:45
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files on the files...