Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-80430— Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory

Quick assessment

Affected
Kovid Goyal kitty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 kitty 终端模拟器版本 0.47.0 至 0.49.0(不含 0.49.0)中,拖放协议(drag and drop protocol)的拖放源暂存路径存在文件访问前链接解析不当的安全漏洞。该漏洞允许向终端写入数据的程序在暂存目录之外的路径创建文件和目录。 具体来说, 中的 函数在解析暂存项子树时,是通过拼接路径字符串并使用 打开该路径,而不是逐个组件地遍历目录树。因此,如果客户端声明两个具有相同名称的条目:第一个是符号链接(symlink),其目标为任意绝对路径;第二个是目录,则 调用会因目标已存在(返回

CVSS 4.6 · Medium EPSS 0.15% · P4
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80430

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the staging directory, because subdir_data_for_drag() in kitty/dnd.c resolves a descendant of the staged item tree by constructing a path string and opening it with safe_open(path, O_DIRECTORY | O_RDONLY, 0) rather than by walking the tree one component at a time, so a client that declares two entries with the same name, the first a symlink whose target is an arbitrary absolute path and the second a directory, causes mkdirat() to fail with EEXIST, which the code ignores, and causes the subsequent path resolution to follow the symlink and return a directory descriptor outside the staging directory, which is then passed as the dirfd argument to add_payload() and used for every further create operation on that item and its descendants. Entry names are sanitised against path separators and dot components, but symlink targets are not validated. Files are created with O_CREAT | O_WRONLY | O_EXCL at mode 0644, so existing files cannot be overwritten, and directories are created with mkdirat() at mode 0755, so the attacker can create intermediate directories that did not previously exist. This results in the creation of files and directories at any path writable by the user running kitty, provided the symlink target is an existing directory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kovid Goyal kitty 0.47.0 ~ 0.49.0 -

II. Public POCs for CVE-2026-80430

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80430

请登录查看更多情报信息。

Other References for CVE-2026-80430 (4)

Same Patch Batch · Kovid Goyal · 2026-09-25 · 6 CVEs total

CVE-2026-95832 9.3 CRITICAL Reflected unknown field names in the kitty colour control escape code allow command execut
CVE-2026-80431 6.8 MEDIUM Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p
CVE-2026-80432 6.0 MEDIUM Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge
CVE-2026-95835 5.6 MEDIUM Missing ownership check on the shared memory object named by the kitty askpass escape code
CVE-2026-95834 4.6 MEDIUM Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-

IV. Related Vulnerabilities

V. Comments for CVE-2026-80430

No comments yet


Leave a comment