Kovidgoyal
Kovidgoyal Kitty: vulnerabilidades y CVE
Kovidgoyal Kitty tiene 9 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses7
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54057 | Alta (7.3) | 0.17% | — | 12 jun 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization.… |
| CVE-2026-54056 | Alta (7.1) | 0.38% | — | 12 jun 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user.… |
| CVE-2026-54055 | Media (5) | 0.10% | — | 12 jun 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the terminal can write… |
| CVE-2026-42851 | Alta (7.8) | 0.19% | — | 12 jun 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered… |
| CVE-2026-42850 | Alta (7.4) | 0.41% | — | 12 jun 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is… |
| CVE-2026-33642 | Crítica (9.8) | 0.43% | — | 19 may 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic… |
| CVE-2026-33633 | Alta (8.8) | 0.46% | — | 19 may 2026 | Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The… |
| CVE-2025-43929 | Alta (7.8) | 0.19% | — | 20 abr 2025 | open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter). |
| CVE-2020-35605 | Crítica (9.8) | 3.8% | — | 21 dic 2020 | The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message. |