Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2026-95835

Medium priority
Needs evaluation

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-95834

Medium priority
Needs evaluation

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory,...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-95832

Medium priority
Needs evaluation

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-80432

Medium priority
Needs evaluation

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-80431

Medium priority
Needs evaluation

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer,...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-80430

Medium priority
Needs evaluation

Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-72913

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-54057

Medium priority

Some fixes available 1 of 2

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Fixed Not affected Not affected Not affected —
Show less packages

CVE-2026-54056

Medium priority
Needs evaluation

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-54055

Medium priority

Some fixes available 2 of 3

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to...

1 affected package

kitty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kitty Fixed Fixed Not affected Not affected —
Show less packages