Command injection in kitty - CVE-2026-42850
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands.
The vulnerability exists due to improper neutralization of special elements used in a command in kitty's error handling for the kitty ssh function when processing a specially crafted kitty escape code received over a connection. A remote attacker can send a specially crafted escape code that injects shell commands to execute arbitrary shell commands.
User interaction is required to establish or accept a connection with the attacker.
Affected software
Debian Linux
kitty (Debian package)
How to mitigate CVE-2026-42850
kitty (Debian package) - update to 0.41.1-2+deb13u2