Browse all 6 CVE security advisories affecting Kovid Goyal. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-95835 | Missing ownership check on the shared memory object named by the kitty askpass escape code — kitty CWE-862 | 5.6 | Medium | 2026-09-25 |
| CVE-2026-95834 | Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-transfer — kitty CWE-416 | 4.6 | Medium | 2026-09-25 |
| CVE-2026-80432 | Missing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a drop — kitty CWE-862 | 6.0 | Medium | 2026-09-25 |
| CVE-2026-80431 | Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process — kitty CWE-787 | 6.8 | Medium | 2026-09-25 |
| CVE-2026-80430 | Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory — kitty CWE-59 | 4.6 | Medium | 2026-09-25 |
| CVE-2026-95832 | Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell — kitty CWE-74 | 9.3 | Critical | 2026-09-25 |
This page lists every published CVE security advisory associated with Kovid Goyal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.