在 kitty 终端模拟器 0.40.0 至 0.49.0(不含 0.49.0)版本中,文本大小写协议的“自然宽度分支”存在一处越界写入漏洞。该漏洞允许向终端写入的程序向固定大小缓冲区末尾之外写入数据。 具体而言,kitty/screen.c 中的 函数在将图形簇(grapheme cluster)的每个码位追加到缓冲区时,执行 操作,但未进行任何容量检查。其中, 是通过 RAII_ListOfChars 宏在函数栈帧中声明的一个包含四个元素的 数组。因此,当 OSC 66 转义码的有效载荷中包含长度超过四个码位的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kovid Goyal | kitty | 0.40.0 ~ 0.49.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95832 | 9.3 CRITICAL | Reflected unknown field names in the kitty colour control escape code allow command execut |
| CVE-2026-80432 | 6.0 MEDIUM | Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge |
| CVE-2026-95835 | 5.6 MEDIUM | Missing ownership check on the shared memory object named by the kitty askpass escape code |
| CVE-2026-80430 | 4.6 MEDIUM | Improper link resolution in the kitty drag and drop protocol allows a client to create fil |
| CVE-2026-95834 | 4.6 MEDIUM | Use after free in the kitty drag and drop protocol when a drag source item is aborted mid- |
No comments yet