在 kitty 终端模拟器版本 0.47.0 至 0.49.0(不含 0.49.0)中,拖放协议(drag and drop protocol)的拖放源暂存路径存在文件访问前链接解析不当的安全漏洞。该漏洞允许向终端写入数据的程序在暂存目录之外的路径创建文件和目录。 具体来说, 中的 函数在解析暂存项子树时,是通过拼接路径字符串并使用 打开该路径,而不是逐个组件地遍历目录树。因此,如果客户端声明两个具有相同名称的条目:第一个是符号链接(symlink),其目标为任意绝对路径;第二个是目录,则 调用会因目标已存在(返回
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kovid Goyal | kitty | 0.47.0 ~ 0.49.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95832 | 9.3 CRITICAL | Reflected unknown field names in the kitty colour control escape code allow command execut |
| CVE-2026-80431 | 6.8 MEDIUM | Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p |
| CVE-2026-80432 | 6.0 MEDIUM | Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge |
| CVE-2026-95835 | 5.6 MEDIUM | Missing ownership check on the shared memory object named by the kitty askpass escape code |
| CVE-2026-95834 | 4.6 MEDIUM | Use after free in the kitty drag and drop protocol when a drag source item is aborted mid- |
No comments yet