Known Vulnerabilities for Kitty by Kitty Project
Listed below are 2 of the newest known vulnerabilities associated with "Kitty" by "Kitty Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-95835 json | Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than th... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-95834 json | Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writ... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-95832 json | Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handle... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-80432 json | Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a pro... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-80431 json | Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a progr... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-80430 json | Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-72913 json | Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2022-41322 json | In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execut... | 7.8 - HIGH | 2022-09-23 | 2023-11-07 |
| CVE-2020-35605 json | The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because ... | 9.8 - CRITICAL | 2020-12-21 | 2022-09-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kitty Project | Kitty | 0.9.1 | |||
| Application | Kitty Project | Kitty | 0.9.0 | |||
| Application | Kitty Project | Kitty | 0.8.4 | |||
| Application | Kitty Project | Kitty | 0.8.3 | |||
| Application | Kitty Project | Kitty | 0.8.2 | |||
| Application | Kitty Project | Kitty | 0.8.1 | |||
| Application | Kitty Project | Kitty | 0.8.0 | |||
| Application | Kitty Project | Kitty | 0.7.1 | |||
| Application | Kitty Project | Kitty | 0.7.0 | |||
| Application | Kitty Project | Kitty | 0.6.1 | |||
| Application | Kitty Project | Kitty | 0.6.0 | |||
| Application | Kitty Project | Kitty | 0.5.1 | |||
| Application | Kitty Project | Kitty | 0.5.0 | |||
| Application | Kitty Project | Kitty | 0.4.2 | |||
| Application | Kitty Project | Kitty | 0.4.1 | |||
| Application | Kitty Project | Kitty | 0.4.0 | |||
| Application | Kitty Project | Kitty | 0.3.0 | |||
| Application | Kitty Project | Kitty | 0.2.8 | |||
| Application | Kitty Project | Kitty | 0.2.7 | |||
| Application | Kitty Project | Kitty | 0.2.6 |