目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-95835— Kitty Askpass 共享内存对象所有权检查缺失漏洞

一分钟漏洞结论

影响对象
Kovid Goyal kitty
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

kitty 终端模拟器中问密码(askpass)转义码处理器存在缺失的授权检查漏洞 在 kitty 终端模拟器 0.25.0 至 0.49.0 版本(不含 0.49.0)中,其问密码(askpass)转义码处理器存在缺失的授权检查(Missing Authorization)漏洞。该漏洞允许除运行 kitty 的终端用户之外的本地用户,获取用户在 kitty 自身显示的提示框中输入的明文内容。 漏洞成因: 问题根源在于 中的 函数。该函数会打开由转义码指定的 POSIX 共享内存对象,从中解析出提示定义,并将用户的

CVSS 5.6 · Medium EPSS 0.10% · P1
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-95835 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Missing ownership check on the shared memory object named by the kitty askpass escape code
来源: CVE Program / CVE List V5
Vulnerability Description
Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_remote_askpass() in kitty/window.py opens the POSIX shared memory object named in the escape code, parses a prompt definition out of it, and writes the user's answer back into an object of that same name, without at any point checking that the object is owned by the user running kitty or that its permissions exclude other users. The equivalent consumer of the same SharedMemory class in the ssh kitten performs exactly that check; the askpass path did not. The handler is reached through a device control string processed from the byte stream of the window, so the attacker must also cause bytes of their choosing to be displayed by the victim's terminal. Where the POSIX shared memory namespace is shared between the two users, a second local user can create an object with permissions that allow the victim to read and write it, cause the victim's kitty to render a prompt of the attacker's choosing, including a masked password prompt, and read the typed secret back out of the object afterwards. The prompt text is additionally passed to the display without control character sanitisation, so it can overwrite the warning line kitty prints above it. The answer is written by reopening an object of that name when the user answers, rather than through the handle already held. This results in disclosure of a secret typed by the victim to a second local user, and does not require any privilege on the victim's account.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Kovid Goyal kitty 0.25.0 ~ 0.49.0 -

二、漏洞 CVE-2026-95835 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-95835 的情报信息

请登录查看更多情报信息。

CVE-2026-95835 其他参考 (3)

同批安全公告 · Kovid Goyal · 2026-09-25 · 共 6 条

CVE-2026-95832 9.3 CRITICAL Kitty终端反射命令执行漏洞
CVE-2026-80431 6.8 MEDIUM Kitty 终端越界写入漏洞
CVE-2026-80432 6.0 MEDIUM Kitty拖放协议缺失授权漏洞
CVE-2026-80430 4.6 MEDIUM Kitty拖放协议链接解析不当导致任意文件创建漏洞
CVE-2026-95834 4.6 MEDIUM Kitty 拖拽协议释放后使用漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-95835

暂无评论


发表评论