Improperly Controlled Modification of Dynamically-Determined Object Attributes in kitty - #VU151625
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete arbitrary directory trees.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the @kitty-edit request parser when processing crafted terminal output. A remote attacker can write crafted DCS escape sequences to a kitty terminal to delete arbitrary directory trees.