Improper Neutralization of Escape, Meta, or Control Sequences in kitty - CVE-2026-54057
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper neutralization of escape, meta, or control sequences in OSC 21 color-control query reply handling when processing a crafted OSC 21 query reply. A remote attacker can provide a query containing newline characters to execute arbitrary commands.
User interaction is required to process crafted terminal content.
Affected software
Debian Linux
kitty (Debian package)
How to mitigate CVE-2026-54057
kitty (Debian package) - update to 0.41.1-2+deb13u2