Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kitty HIGH 7.8
CVE-2026-54057

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled by…

Fix: 0.47.3+
Fix from $1,950 2026-06-12
Kitty HIGH 7.1
CVE-2026-54056

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwr…

Fix: 0.47.2+
Fix from $1,950 2026-06-12
Kitty MEDIUM 5.0
CVE-2026-54055

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmis…

Fix: 0.47.2+
Fix from $1,600 2026-06-12
Kitty HIGH 8.8
CVE-2026-42850

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error.…

Fix: 0.47.0+
Fix from $1,950 2026-06-12
Kitty HIGH 7.8
CVE-2026-42851

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a d…

Fix: 0.47.0+
Fix from $1,950 2026-06-12
Kitty CRITICAL 9.8
CVE-2026-33642

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds…

Fix: 0.47.0+
Fix from $2,300 2026-05-19
Kitty HIGH 8.8
CVE-2026-33633

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process w…

Fix: 0.47.0+
Fix from $1,950 2026-05-19
Kitty HIGH 7.8
CVE-2025-43929

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an un…

Fix: 0.41.0+
Fix from $1,950 2025-04-20