Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95835— Missing ownership check on the shared memory object named by the kitty askpass escape code

Quick assessment

Affected
Kovid Goyal kitty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

kitty 终端模拟器中问密码(askpass)转义码处理器存在缺失的授权检查漏洞 在 kitty 终端模拟器 0.25.0 至 0.49.0 版本(不含 0.49.0)中,其问密码(askpass)转义码处理器存在缺失的授权检查(Missing Authorization)漏洞。该漏洞允许除运行 kitty 的终端用户之外的本地用户,获取用户在 kitty 自身显示的提示框中输入的明文内容。 漏洞成因: 问题根源在于 中的 函数。该函数会打开由转义码指定的 POSIX 共享内存对象,从中解析出提示定义,并将用户的

CVSS 5.6 · Medium EPSS 0.10% · P1
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing ownership check on the shared memory object named by the kitty askpass escape code
Source: CVE Program / CVE List V5
Vulnerability Description
Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_remote_askpass() in kitty/window.py opens the POSIX shared memory object named in the escape code, parses a prompt definition out of it, and writes the user's answer back into an object of that same name, without at any point checking that the object is owned by the user running kitty or that its permissions exclude other users. The equivalent consumer of the same SharedMemory class in the ssh kitten performs exactly that check; the askpass path did not. The handler is reached through a device control string processed from the byte stream of the window, so the attacker must also cause bytes of their choosing to be displayed by the victim's terminal. Where the POSIX shared memory namespace is shared between the two users, a second local user can create an object with permissions that allow the victim to read and write it, cause the victim's kitty to render a prompt of the attacker's choosing, including a masked password prompt, and read the typed secret back out of the object afterwards. The prompt text is additionally passed to the display without control character sanitisation, so it can overwrite the warning line kitty prints above it. The answer is written by reopening an object of that name when the user answers, rather than through the handle already held. This results in disclosure of a secret typed by the victim to a second local user, and does not require any privilege on the victim's account.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kovid Goyal kitty 0.25.0 ~ 0.49.0 -

II. Public POCs for CVE-2026-95835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95835

请登录查看更多情报信息。

Other References for CVE-2026-95835 (3)

Same Patch Batch · Kovid Goyal · 2026-09-25 · 6 CVEs total

CVE-2026-95832 9.3 CRITICAL Reflected unknown field names in the kitty colour control escape code allow command execut
CVE-2026-80431 6.8 MEDIUM Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal p
CVE-2026-80432 6.0 MEDIUM Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge
CVE-2026-80430 4.6 MEDIUM Improper link resolution in the kitty drag and drop protocol allows a client to create fil
CVE-2026-95834 4.6 MEDIUM Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-

IV. Related Vulnerabilities

V. Comments for CVE-2026-95835

No comments yet


Leave a comment