By vendor
Kovidgoyal vulnerabilities
Known CVEs affecting Kovidgoyal products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-42850HIGH 8.8
Kitty, a GPU-accelerated terminal emulator used across multiple platforms, contains a command injection vulnerability in versions before 0.47.0. An attacker can craft a malicious escape sequence that causes Kitty to generate an unescaped error message. When this error is echoed back to the shell, it executes as a command, allowing arbitrary code execution. The attack requires the victim to be connected to the attacker via netcat or similar network tool, or to initiate a connection to the attacker's system. This is a serious but not immediately widespread threat—it depends on a specific usage pattern and user interaction.