Kovidgoyal Kitty vulnerabilities
9 known vulnerabilities affecting kovidgoyal/kitty.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-35605P3CRITICALCVSS 9.8fixed in 0.19.32020-12-21
CVE-2020-35605 [CRITICAL] CVE-2020-35605: The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execut
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
nvdosv
CVE-2026-33642P3CRITICALCVSS 9.8fixed in 0.47.02026-05-19
CVE-2026-33642 [CRITICAL] CWE-125 CVE-2026-33642: Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_comma
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Heap Buffer Over-Read/Write. An attacker who can write escape sequences
nvd
CVE-2026-42850P3HIGHCVSS 8.8fixed in 0.47.02026-06-12
CVE-2026-42850 [HIGH] CWE-77 CVE-2026-42850: Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal with CRLF, as such it will be run by the shell in use. To exploit this bug
nvd
CVE-2026-33633P3HIGHCVSS 8.8fixed in 0.47.02026-05-19
CVE-2026-33633 [HIGH] CWE-122 CVE-2026-33633: Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overfl
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twic
nvd
CVE-2026-54057P3HIGHCVSS 7.8fixed in 0.47.32026-06-12
CVE-2026-54057 [HIGH] CWE-94 CVE-2026-54057: Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-con
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.
nvd
CVE-2026-42851P3HIGHCVSS 7.8fixed in 0.47.02026-06-12
CVE-2026-42851 [HIGH] CWE-94 CVE-2026-42851: Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write b
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to execute attacker-supplied Python inside the running kitty process, with the
nvd
CVE-2026-54056P3HIGHCVSS 7.1≥ 0.47.0, < 0.47.2v>= 0.47.0, < 0.47.22026-06-12
CVE-2026-54056 [HIGH] CWE-59 CVE-2026-54056: Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow
Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote `text/uri-list` drops are staged in a temporary directory, but on case-sensitive filesystems duplicate remote basenames are not de-du
nvd
CVE-2025-43929P3HIGHCVSS 7.8fixed in 0.41.02025-04-20
CVE-2025-43929 [HIGH] CWE-346 CVE-2025-43929: open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local exe
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
nvd
CVE-2026-54055P4MEDIUMCVSS 5.0fixed in 0.47.22026-06-12
CVE-2026-54055 [MEDIUM] CWE-59 CVE-2026-54055: Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalat
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write to arbitrary files on the filesystem by exploiting a TOCTOU (Time-of-Check-Time-of-Use) race condition between symlink validation and
nvd