Link following in kitty - CVE-2026-54055
Published: September 22, 2026
Vulnerability details
The vulnerability allows a local user to write to arbitrary user-writable files.
The vulnerability exists due to improper link resolution before file access in the DestFile.write_data() method of kitty/file_transmission.py when processing file transmission data after validating a destination path. A local user can create a symlink after the initial validation and send file transmission data to write through the symlink.
User interaction is required to confirm the file transfer.
Affected software
Debian Linux
kitty (Debian package)
How to mitigate CVE-2026-54055
kitty (Debian package) - update to 0.41.1-2+deb13u2