VendorsKovidgoyalkittyany version
Vulnerabilities

Kovidgoyal Kitty any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-33642
Kitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds Check
Published 2026-05-19 · Analyzed
9.9EPSS 0.004
CVE-2020-35605
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
Published 2020-12-21 · Modified
9.8EPSS 0.038
CVE-2026-33633
Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler
Published 2026-05-19 · Analyzed
8.8EPSS 0.005
CVE-2026-42850
Kitty has a shell command injection
Published 2026-06-12 · Analyzed
8.8EPSS 0.004
CVE-2026-54057
Kitty vulnerable to command injection via unsanitized OSC 21 query reply
Published 2026-06-12 · Analyzed
7.8EPSS 0.002
CVE-2026-42851
@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE
Published 2026-06-12 · Analyzed
7.8EPSS 0.002
CVE-2025-43929
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
Published 2025-04-20 · Analyzed
7.8EPSS 0.002
CVE-2026-54056
Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop staging
Published 2026-06-12 · Analyzed
7.6EPSS 0.004
CVE-2026-54055
Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol
Published 2026-06-12 · Analyzed
5.0EPSS 0.001