SB2026092261 - Multiple vulnerabilities in kitty



SB2026092261 - Multiple vulnerabilities in kitty

Published: September 22, 2026

Security Bulletin ID SB2026092261
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to execute commands as the user running kitty.

The vulnerability exists due to missing authorization in the abstract AF_UNIX socket used by the --single-instance feature when processing commands received from local processes. A local attacker can connect to the socket and send commands to execute commands as the user running kitty.

Exploitation requires sharing the host's network namespace with kitty.


2) Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-ID: N/A)

CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to delete arbitrary directory trees.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the @kitty-edit request parser when processing crafted terminal output. A remote attacker can write crafted DCS escape sequences to a kitty terminal to delete arbitrary directory trees.


Remediation

Install update from vendor's website.