Missing ownership check on the shared memory object named by the kitty askpass escape code

Summary

CVECVE-2026-95835
StatePUBLISHED
AssignerSecur0
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 17:17:20 UTC
Updated2026-09-25 18:17:33 UTC
DescriptionMissing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_remote_askpass() in kitty/window.py opens the POSIX shared memory object named in the escape code, parses a prompt definition out of it, and writes the user's answer back into an object of that same name, without at any point checking that the object is owned by the user running kitty or that its permissions exclude other users. The equivalent consumer of the same SharedMemory class in the ssh kitten performs exactly that check; the askpass path did not. The handler is reached through a device control string processed from the byte stream of the window, so the attacker must also cause bytes of their choosing to be displayed by the victim's terminal. Where the POSIX shared memory namespace is shared between the two users, a second local user can create an object with permissions that allow the victim to read and write it, cause the victim's kitty to render a prompt of the attacker's choosing, including a masked password prompt, and read the typed secret back out of the object afterwards. The prompt text is additionally passed to the display without control character sanitisation, so it can overwrite the warning line kitty prints above it. The answer is written by reopening an object of that name when the user answers, rather than through the handle already held. This results in disclosure of a secret typed by the victim to a second local user, and does not require any privilege on the victim's account.

Risk And Classification

Primary CVSS: v4.0 5.6 MEDIUM from 4daa8cea-433a-44bd-9456-53b127fc289a

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS: 0.001000000 probability, percentile 0.007850000 (date 2026-09-27)

Problem Types: CWE-862 | CWE-862 CWE-862 Missing Authorization


VersionSourceTypeScoreSeverityVector
4.04daa8cea-433a-44bd-9456-53b127fc289aSecondary5.6MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/C...
4.0CNACVSS5.6MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N

CVSS v4.0 Breakdown

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
Active
Confidentiality
High
Integrity
Low
Availability
None
Sub Conf.
High
Sub Integrity
None
Sub Availability
None

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Kovid Goyal Kitty affected 0.25.0 0.49.0 semver Not specified

References

ReferenceSourceLinkTags
secur0.com/en/cna/cve-list/cve-2026-95835-kitty-askpass-shared-memory-ow... 4daa8cea-433a-44bd-9456-53b127fc289a secur0.com
github.com/kovidgoyal/kitty/releases/tag/v0.49.0 4daa8cea-433a-44bd-9456-53b127fc289a github.com
github.com/kovidgoyal/kitty/commit/3281919056c442e4ba6f5abed7ee2c5130de31ff 4daa8cea-433a-44bd-9456-53b127fc289a github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Gabriel Machado Tavares (en)

CNA: Cristian Fernández Cornejo (en)

CNA: Xoán M. Otero Jorge (en)

CNA: Secur0 CNA (en)

CNA: Kovid Goyal (en)

Additional Advisory Data

Solutions

CNA: Upgrade to kitty 0.49.0 or later. Only systems on which the two users share a POSIX shared memory namespace are exposed to the cross-user case; a session confined to its own mount namespace with its own /dev/shm, as in a container, is not.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report