Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2026-54057

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54056

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54055

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42851

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`,...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42850

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33642

Medium priority
Vulnerable

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2026-33633

Medium priority
Vulnerable

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately....

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-43929

Medium priority
Needs evaluation

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Not affected Ignored Not affected Not affected
Show less packages

CVE-2022-41322

Medium priority

Some fixes available 1 of 3

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Fixed Not affected Not in release
Show less packages

CVE-2021-25322

Medium priority
Needs evaluation

A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects:...

1 affected package

hyperkitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hyperkitty Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
Show less packages