以下是该漏洞描述信息的中文翻译: 在 kitty 终端模拟器 0.47.3 至 0.49.0 版本之前(不含 0.49.0)的颜色控制转义码处理程序中,存在一个“在下游组件使用的输出中未正确中和特殊元素”的安全漏洞。该漏洞允许向终端写入数据的程序在用户 Shell 中执行任意命令。原因是 kitty/window.py 中的 color_control() 函数在对未识别字段名称的查询做出响应时,会将该字段名称直接放入回复内容中;随后,kitty/screen.c 中的 write_escape_code_to_c
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kovid Goyal | kitty | 0.47.3 ~ 0.49.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80431 | 6.8 MEDIUM | Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p |
| CVE-2026-80432 | 6.0 MEDIUM | Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge |
| CVE-2026-95835 | 5.6 MEDIUM | Missing ownership check on the shared memory object named by the kitty askpass escape code |
| CVE-2026-80430 | 4.6 MEDIUM | Improper link resolution in the kitty drag and drop protocol allows a client to create fil |
| CVE-2026-95834 | 4.6 MEDIUM | Use after free in the kitty drag and drop protocol when a drag source item is aborted mid- |
No comments yet