在 kitty 终端模拟器 0.47.0 至 0.49.0(不含 0.49.0)版本中,拖放协议的处理路径中存在缺失授权检查的安全漏洞。该漏洞使得向终端写入数据的程序能够获取拖放至窗口上方的文件内容,即使用户从未完成实际的拖放操作。 具体而言,在 kitty/dnd.c 文件中, 函数在处理拖放数据请求时,未先检查窗口的拖放状态,便直接响应了拖放数据请求。因此,当一个客户端在拖放操作仅处于悬停(hover)状态时发出请求,即可获得本次拖放所提供的数据。 在同一文件中,当拖放操作离开窗口且未发生实际拖放时,会执行 函
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kovid Goyal | kitty | 0.47.0 ~ 0.49.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95832 | 9.3 CRITICAL | Reflected unknown field names in the kitty colour control escape code allow command execut |
| CVE-2026-80431 | 6.8 MEDIUM | Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p |
| CVE-2026-95835 | 5.6 MEDIUM | Missing ownership check on the shared memory object named by the kitty askpass escape code |
| CVE-2026-80430 | 4.6 MEDIUM | Improper link resolution in the kitty drag and drop protocol allows a client to create fil |
| CVE-2026-95834 | 4.6 MEDIUM | Use after free in the kitty drag and drop protocol when a drag source item is aborted mid- |
No comments yet