Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kitty — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in kitty, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with the product kitty, focusing primarily on memory corruption and input validation weaknesses commonly found in terminal emulation software. The collection spans multiple years, compiling disclosures from initial release versions through recent stable builds to provide a comprehensive historical context of the software's security posture. Readers can utilize this data to track the vendor's advisory patterns over time, analyze the prevalence of specific weakness classes such as buffer overflows within the codebase, and review the complete vulnerability history of the application to assess its long-term reliability and patch responsiveness. By examining these aggregated records, security professionals and developers can identify recurring themes in reported issues, understand the evolution of the product's security controls, and evaluate the effectiveness of remediation strategies implemented by the maintainers across different release cycles. This resource serves as a neutral, factual compilation of public vulnerability reports, enabling informed risk assessment without editorial commentary or promotional framing.

Vendor: kitty project

CVE ID Title CVSS Severity Published
CVE-2026-95835 Missing ownership check on the shared memory object named by the kitty askpass escape code CWE-862 5.6 Medium 2026-09-25
CVE-2026-95834 Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-transfer CWE-416 4.6 Medium 2026-09-25
CVE-2026-80432 Missing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a drop CWE-862 6.0 Medium 2026-09-25
CVE-2026-80431 Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process CWE-787 6.8 Medium 2026-09-25
CVE-2026-80430 Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory CWE-59 4.6 Medium 2026-09-25
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell CWE-74 9.3 Critical 2026-09-25
CVE-2026-72913 Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences CWE-77 7.3 High 2026-08-10
CVE-2026-54057 Kitty vulnerable to command injection via unsanitized OSC 21 query reply CWE-94 - - 2026-06-12
CVE-2026-54056 Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop staging CWE-59 7.6 High 2026-06-12
CVE-2026-54055 Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol CWE-59 5.0 Medium 2026-06-12
CVE-2026-42851 @kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE CWE-94 7.8 High 2026-06-12
CVE-2026-42850 Kitty has a shell command injection CWE-77 - - 2026-06-12
CVE-2026-33642 Kitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds Check CWE-190 9.9 Critical 2026-05-19
CVE-2026-33633 Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler CWE-122 7.5 High 2026-05-19
CVE-2025-43929 kitty 安全漏洞 CWE-346 4.1 Medium 2025-04-20

All 15 known CVE vulnerabilities affecting kitty with full Chinese analysis, references, and POCs where available.