目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-95832— Kitty终端反射命令执行漏洞

一分钟漏洞结论

影响对象
Kovid Goyal kitty
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述信息的中文翻译: 在 kitty 终端模拟器 0.47.3 至 0.49.0 版本之前(不含 0.49.0)的颜色控制转义码处理程序中,存在一个“在下游组件使用的输出中未正确中和特殊元素”的安全漏洞。该漏洞允许向终端写入数据的程序在用户 Shell 中执行任意命令。原因是 kitty/window.py 中的 color_control() 函数在对未识别字段名称的查询做出响应时,会将该字段名称直接放入回复内容中;随后,kitty/screen.c 中的 write_escape_code_to_c

CVSS 9.3 · Critical EPSS 0.16% · P5
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-95832 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell
来源: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in the user's shell, because color_control() in kitty/window.py answers a query for an unrecognised field name by placing that field name into the reply, and write_escape_code_to_child() in kitty/screen.c then writes the reply to the pseudoterminal master, where it is not distinguishable from input typed by the user, without neutralising it for the shell that reads it. The payload is reduced to printable ASCII before the field name is echoed, which is the restriction introduced in 0.47.3 as the fix for CVE-2026-54057, and the record and field separators ; and = are consumed as delimiters, but every other printable character survives, which is sufficient to compose a shell command. A newline is available from handle_remote_ssh() in kitty/window.py, which writes the bytes yielded by get_ssh_data() in kittens/ssh/utils.py, the first of which begin with a newline, to the pseudoterminal master before any credential carried in the request is checked. The reply is framed as an OSC sequence carrying the escape code number, the field name, and the literal value ?. This results in execution of an attacker-chosen command with the privileges of the user running the terminal.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
来源: CVE Program / CVE List V5
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Kovid Goyal kitty 0.47.3 ~ 0.49.0 -

二、漏洞 CVE-2026-95832 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-95832 的情报信息

请登录查看更多情报信息。

CVE-2026-95832 其他参考 (1)

CVE-2026-95832 其他参考 (4)

同批安全公告 · Kovid Goyal · 2026-09-25 · 共 6 条

CVE-2026-80431 6.8 MEDIUM Kitty 终端越界写入漏洞
CVE-2026-80432 6.0 MEDIUM Kitty拖放协议缺失授权漏洞
CVE-2026-95835 5.6 MEDIUM Kitty Askpass 共享内存对象所有权检查缺失漏洞
CVE-2026-80430 4.6 MEDIUM Kitty拖放协议链接解析不当导致任意文件创建漏洞
CVE-2026-95834 4.6 MEDIUM Kitty 拖拽协议释放后使用漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-95832

暂无评论


发表评论