By vendor

Kovidgoyal vulnerabilities

Known CVEs affecting Kovidgoyal products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-42850HIGH 8.8

    Kitty, a GPU-accelerated terminal emulator used across multiple platforms, contains a command injection vulnerability in versions before 0.47.0. An attacker can craft a malicious escape sequence that causes Kitty to generate an unescaped error message. When this error is echoed back to the shell, it executes as a command, allowing arbitrary code execution. The attack requires the victim to be connected to the attacker via netcat or similar network tool, or to initiate a connection to the attacker's system. This is a serious but not immediately widespread threat—it depends on a specific usage pattern and user interaction.