Kovidgoyal kitty是Kovidgoyal个人开发者开源的一个基于Python的GPU终端仿真软件。 该软件可提供基本的终端功能,并且基于GPU渲染可降低系统负载,采用OpenGL进行渲染,可支持在Linux、Mac上使用。 kovidgoyal kitty 0.47.0之前版本存在命令注入漏洞,该漏洞源于错误信息未进行转义,可能导致命令注入攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kovidgoyal | kitty | < 0.47.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kovidgoyal | kitty | < 0.47.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42851 | 7.8 HIGH | @kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE |
| CVE-2026-54056 | 7.6 HIGH | Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop st |
| CVE-2026-54055 | 5.0 MEDIUM | Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol |
| CVE-2026-54057 | Kitty vulnerable to command injection via unsanitized OSC 21 query reply |
No comments yet