Missing Authorization in kitty - #VU151624
Published: September 22, 2026
Vulnerability details
The vulnerability allows a local attacker to execute commands as the user running kitty.
The vulnerability exists due to missing authorization in the abstract AF_UNIX socket used by the --single-instance feature when processing commands received from local processes. A local attacker can connect to the socket and send commands to execute commands as the user running kitty.
Exploitation requires sharing the host's network namespace with kitty.