Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-80432— Missing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a drop

Quick assessment

Affected
Kovid Goyal kitty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 kitty 终端模拟器 0.47.0 至 0.49.0(不含 0.49.0)版本中,拖放协议的处理路径中存在缺失授权检查的安全漏洞。该漏洞使得向终端写入数据的程序能够获取拖放至窗口上方的文件内容,即使用户从未完成实际的拖放操作。 具体而言,在 kitty/dnd.c 文件中, 函数在处理拖放数据请求时,未先检查窗口的拖放状态,便直接响应了拖放数据请求。因此,当一个客户端在拖放操作仅处于悬停(hover)状态时发出请求,即可获得本次拖放所提供的数据。 在同一文件中,当拖放操作离开窗口且未发生实际拖放时,会执行 函

CVSS 6.0 · Medium EPSS 0.12% · P2
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80432

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a drop
Source: CVE Program / CVE List V5
Vulnerability Description
Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never completes the drop, because drop_enqueue_request() in kitty/dnd.c serves a drag data request without first checking the drop state of the window, so a client that issues the request while a drag is merely hovering receives the data offered for the drag. In the same file, drop_left_child(), which runs when the drag leaves the window without a drop having occurred, releases the offered MIME list but retains the pending request state, the open file descriptor and its main loop transfer timer, the directory handles, the URI list and the pending MIME name, so a client can continue to read through a retained directory handle, and an in-flight file transfer continues to stream, when no drag is in progress. The file contents are read from the filesystem by the kitty process itself using the paths the drag source offered. This results in disclosure of the contents of files the user moved over the window without ever releasing them into it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kovid Goyal kitty 0.47.0 ~ 0.49.0 -

II. Public POCs for CVE-2026-80432

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80432

请登录查看更多情报信息。

Other References for CVE-2026-80432 (3)

Same Patch Batch · Kovid Goyal · 2026-09-25 · 6 CVEs total

CVE-2026-95832 9.3 CRITICAL Reflected unknown field names in the kitty colour control escape code allow command execut
CVE-2026-80431 6.8 MEDIUM Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p
CVE-2026-95835 5.6 MEDIUM Missing ownership check on the shared memory object named by the kitty askpass escape code
CVE-2026-80430 4.6 MEDIUM Improper link resolution in the kitty drag and drop protocol allows a client to create fil
CVE-2026-95834 4.6 MEDIUM Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-

IV. Related Vulnerabilities

V. Comments for CVE-2026-80432

No comments yet


Leave a comment