Link following in kitty - CVE-2026-54056

 

Link following in kitty - CVE-2026-54056

Published: September 22, 2026


Vulnerability identifier: #VU151618
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54056
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite or truncate arbitrary files writable by the local kitty user.

The vulnerability exists due to improper link resolution before file access in the kitten dnd remote drag-and-drop staging code when processing remote text/uri-list drops with duplicate basenames. A remote user can create a staged symlink and then send a same-name regular-file entry to overwrite or truncate arbitrary files writable by the local kitty user.

User interaction is required to perform the remote drag-and-drop action.


Affected software

kitty

How to mitigate CVE-2026-54056

Install security update from vendor's website.

kitty - update to 0.47.2

External References

Related Security Bulletins