SB2026092261 - Multiple vulnerabilities in kitty
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to execute commands as the user running kitty.
The vulnerability exists due to missing authorization in the abstract AF_UNIX socket used by the --single-instance feature when processing commands received from local processes. A local attacker can connect to the socket and send commands to execute commands as the user running kitty.
Exploitation requires sharing the host's network namespace with kitty.
2) Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-ID: N/A)
CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to delete arbitrary directory trees.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the @kitty-edit request parser when processing crafted terminal output. A remote attacker can write crafted DCS escape sequences to a kitty terminal to delete arbitrary directory trees.
Remediation
Install update from vendor's website.