CVE-2022-41322
published 2022-09-23CVE-2022-41322: In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.48%
38.3th percentile
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kitty | < kitty 0.21.2-2 (bookworm) | kitty 0.21.2-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| kitty_project | kitty | < 0.26.2 | 0.26.2 |
| kitty_project | kitty | >= 0 < 0.19.3-1+deb11u1 | 0.19.3-1+deb11u1 |
| kitty_project | kitty | >= 0 < 0.21.2-2 | 0.21.2-2 |
| kitty_project | kitty | >= 0 < 0.21.2-2 | 0.21.2-2 |
| kitty_project | kitty | >= 0 < 0.21.2-2 | 0.21.2-2 |
| kovidgoyal | kitty | >= 0 < 0.15.0-1ubuntu0.2 | 0.15.0-1ubuntu0.2 |
| kovidgoyal | kitty | >= 0 < 0.21.2-1ubuntu0.22.04.1 | 0.21.2-1ubuntu0.22.04.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
kitty vulnerabilities
vendor_ubuntu·2022-10-05·CVSS 9.8
CVE-2022-41322 [CRITICAL] kitty vulnerabilities
Title: kitty vulnerabilities
Summary: kitty could be made to run programs if it opened a specially
crafted image or desktop notification.
Stephane Chauveau discovered that kitty incorrectly handled image
filenames with special characters in error messages. A remote
attacker could possibly use this to execute arbitrary commands.
This issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605)
Carter Sande discovered that kitty incorrectly handled escape
sequences in desktop notifications. A remote attacker could possibly
use this to execute arbitrary commands. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-41322)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-41322: kitty - In Kitty before 0.26.2, insufficient validation in the desktop notification esca...
vendor_debian·2022·CVSS 7.8
CVE-2022-41322 [HIGH] CVE-2022-41322: kitty - In Kitty before 0.26.2, insufficient validation in the desktop notification esca...
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Scope: local
bookworm: resolved (fixed in 0.21.2-2)
bullseye: resolved (fixed in 0.19.3-1+deb11u1)
forky: resolved (fixed in 0.21.2-2)
sid: resolved (fixed in 0.21.2-2)
trixie: resolved (fixed in 0.21.2-2)
OSV
kitty vulnerabilities
osv·2022-10-05·CVSS 9.8
CVE-2020-35605 [CRITICAL] kitty vulnerabilities
kitty vulnerabilities
Stephane Chauveau discovered that kitty incorrectly handled image
filenames with special characters in error messages. A remote
attacker could possibly use this to execute arbitrary commands.
This issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605)
Carter Sande discovered that kitty incorrectly handled escape
sequences in desktop notifications. A remote attacker could possibly
use this to execute arbitrary commands. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-41322)
GHSA
GHSA-5v8v-cp6r-mq7c: In Kitty before 0
ghsa_unreviewed·2022-09-25
CVE-2022-41322 [HIGH] CWE-116 GHSA-5v8v-cp6r-mq7c: In Kitty before 0
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
OSV
CVE-2022-41322: In Kitty before 0
osv·2022-09-23·CVSS 7.8
CVE-2022-41322 [HIGH] CVE-2022-41322: In Kitty before 0
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.gentoo.org/868543https://github.com/kovidgoyal/kitty/commit/f05783e64d5fa62e1aed603e8d69aced5e49824fhttps://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RRNAPU33PHEH64P77YL3AJO6CTZGHTX/https://security.gentoo.org/glsa/202209-22https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changeshttps://bugs.gentoo.org/868543https://github.com/kovidgoyal/kitty/commit/f05783e64d5fa62e1aed603e8d69aced5e49824fhttps://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2https://lists.debian.org/debian-lts-announce/2025/06/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RRNAPU33PHEH64P77YL3AJO6CTZGHTX/https://security.gentoo.org/glsa/202209-22https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes
2022-09-23
Published