Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95832— Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell

Quick assessment

Affected
Kovid Goyal kitty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 kitty 终端模拟器 0.47.3 至 0.49.0 版本之前(不含 0.49.0)的颜色控制转义码处理程序中,存在一个“在下游组件使用的输出中未正确中和特殊元素”的安全漏洞。该漏洞允许向终端写入数据的程序在用户 Shell 中执行任意命令。原因是 kitty/window.py 中的 color_control() 函数在对未识别字段名称的查询做出响应时,会将该字段名称直接放入回复内容中;随后,kitty/screen.c 中的 write_escape_code_to_c

CVSS 9.3 · Critical EPSS 0.16% · P5
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95832

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in the user's shell, because color_control() in kitty/window.py answers a query for an unrecognised field name by placing that field name into the reply, and write_escape_code_to_child() in kitty/screen.c then writes the reply to the pseudoterminal master, where it is not distinguishable from input typed by the user, without neutralising it for the shell that reads it. The payload is reduced to printable ASCII before the field name is echoed, which is the restriction introduced in 0.47.3 as the fix for CVE-2026-54057, and the record and field separators ; and = are consumed as delimiters, but every other printable character survives, which is sufficient to compose a shell command. A newline is available from handle_remote_ssh() in kitty/window.py, which writes the bytes yielded by get_ssh_data() in kittens/ssh/utils.py, the first of which begin with a newline, to the pseudoterminal master before any credential carried in the request is checked. The reply is framed as an OSC sequence carrying the escape code number, the field name, and the literal value ?. This results in execution of an attacker-chosen command with the privileges of the user running the terminal.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kovid Goyal kitty 0.47.3 ~ 0.49.0 -

II. Public POCs for CVE-2026-95832

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95832

请登录查看更多情报信息。

Other References for CVE-2026-95832 (1)

Other References for CVE-2026-95832 (4)

Same Patch Batch · Kovid Goyal · 2026-09-25 · 6 CVEs total

CVE-2026-80431 6.8 MEDIUM Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p
CVE-2026-80432 6.0 MEDIUM Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge
CVE-2026-95835 5.6 MEDIUM Missing ownership check on the shared memory object named by the kitty askpass escape code
CVE-2026-80430 4.6 MEDIUM Improper link resolution in the kitty drag and drop protocol allows a client to create fil
CVE-2026-95834 4.6 MEDIUM Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-

IV. Related Vulnerabilities

V. Comments for CVE-2026-95832

No comments yet


Leave a comment