kitty 终端模拟器中问密码(askpass)转义码处理器存在缺失的授权检查漏洞 在 kitty 终端模拟器 0.25.0 至 0.49.0 版本(不含 0.49.0)中,其问密码(askpass)转义码处理器存在缺失的授权检查(Missing Authorization)漏洞。该漏洞允许除运行 kitty 的终端用户之外的本地用户,获取用户在 kitty 自身显示的提示框中输入的明文内容。 漏洞成因: 问题根源在于 中的 函数。该函数会打开由转义码指定的 POSIX 共享内存对象,从中解析出提示定义,并将用户的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kovid Goyal | kitty | 0.25.0 ~ 0.49.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95832 | 9.3 CRITICAL | Reflected unknown field names in the kitty colour control escape code allow command execut |
| CVE-2026-80431 | 6.8 MEDIUM | Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p |
| CVE-2026-80432 | 6.0 MEDIUM | Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge |
| CVE-2026-80430 | 4.6 MEDIUM | Improper link resolution in the kitty drag and drop protocol allows a client to create fil |
| CVE-2026-95834 | 4.6 MEDIUM | Use after free in the kitty drag and drop protocol when a drag source item is aborted mid- |
No comments yet