{"id":"USN-8763-1","summary":"kitty vulnerabilities","details":"It was discovered that kitty incorrectly escaped error messages when\nhandling specially crafted terminal escape sequences. A remote attacker\ncould possibly use this issue to execute arbitrary commands.\n(CVE-2026-42850)\n\nIt was discovered that kitty incorrectly handled remote edit requests in\nterminal output. An attacker could possibly use this issue to execute\narbitrary code with the user's privileges.\n(CVE-2026-42851)\n\nThai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly\nhandled destination paths in its file transmission protocol. A local\nattacker could possibly use this issue to overwrite arbitrary files with\nthe user's privileges.\n(CVE-2026-54055)\n\nIt was discovered that kitty incorrectly sanitized responses to color\nqueries. An attacker could possibly use this issue to execute arbitrary\ncommands with the user's privileges. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-54057)","modified":"2026-09-16T02:57:27.385295756Z","published":"2026-09-15T13:31:45Z","related":["UBUNTU-CVE-2026-42850","UBUNTU-CVE-2026-42851","UBUNTU-CVE-2026-54055","UBUNTU-CVE-2026-54057"],"upstream":["CVE-2026-42850","CVE-2026-42851","CVE-2026-54055","CVE-2026-54057","UBUNTU-CVE-2026-42850","UBUNTU-CVE-2026-42851","UBUNTU-CVE-2026-54055","UBUNTU-CVE-2026-54057"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8763-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42850"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42851"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-54055"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-54057"}],"affected":[{"package":{"name":"kitty","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.32.2-1ubuntu0.4+esm2"}]}],"versions":["0.26.5-3ubuntu2","0.26.5-5ubuntu1","0.31.0-3","0.31.0-4","0.32.2-1","0.32.2-1build2","0.32.2-1build3","0.32.2-1ubuntu0.1","0.32.2-1ubuntu0.2","0.32.2-1ubuntu0.3","0.32.2-1ubuntu0.4","0.32.2-1ubuntu0.4+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"kitty","binary_version":"0.32.2-1ubuntu0.4+esm2"},{"binary_name":"kitty-shell-integration","binary_version":"0.32.2-1ubuntu0.4+esm2"},{"binary_name":"kitty-terminfo","binary_version":"0.32.2-1ubuntu0.4+esm2"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42850"},{"id":"CVE-2026-42851","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-54055"}],"ecosystem":"Ubuntu:Pro:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8763-1.json"}},{"package":{"name":"kitty","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.45.0-1ubuntu0.1~esm2"}]}],"versions":["0.41.1-2","0.43.1-1","0.44.0-1","0.45.0-1","0.45.0-1build1","0.45.0-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"kitty","binary_version":"0.45.0-1ubuntu0.1~esm2"},{"binary_name":"kitty-shell-integration","binary_version":"0.45.0-1ubuntu0.1~esm2"},{"binary_version":"0.45.0-1ubuntu0.1~esm2","binary_name":"kitty-terminfo"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8763-1.json","cves_map":{"cves":[{"id":"CVE-2026-42850","severity":[{"score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42851"},{"id":"CVE-2026-54055","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-54057","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:Pro:26.04:LTS"}}}],"schema_version":"1.9.0"}