Link following in kitty - CVE-2026-54056
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite or truncate arbitrary files writable by the local kitty user.
The vulnerability exists due to improper link resolution before file access in the kitten dnd remote drag-and-drop staging code when processing remote text/uri-list drops with duplicate basenames. A remote user can create a staged symlink and then send a same-name regular-file entry to overwrite or truncate arbitrary files writable by the local kitty user.
User interaction is required to perform the remote drag-and-drop action.