Missing Authorization in kitty - #VU151624

 

Missing Authorization in kitty - #VU151624

Published: September 22, 2026


Vulnerability identifier: #VU151624
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute commands as the user running kitty.

The vulnerability exists due to missing authorization in the abstract AF_UNIX socket used by the --single-instance feature when processing commands received from local processes. A local attacker can connect to the socket and send commands to execute commands as the user running kitty.

Exploitation requires sharing the host's network namespace with kitty.


Affected software

kitty

Remediation

Install security update from vendor's website.

kitty - update to 0.49.0

External References

Related Security Bulletins