Kitty Kovidgoyal Kitty

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Kovidgoyal Kitty.

By the Year

In 2026 there have been 0 vulnerabilities in Kovidgoyal Kitty. Last year, in 2025 Kitty had 1 security vulnerability published. Right now, Kitty is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 1 7.80
2024 0 0.00
2023 0 0.00
2022 1 7.80
2021 0 0.00
2020 1 9.80

It may take a day or so for new Kitty vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Kovidgoyal Kitty Security Vulnerabilities

Open_actions.py in kitty <0.41 execs untrusted docs without confirm
CVE-2025-43929 7.8 - High - April 20, 2025

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

Origin Validation Error

Kitty <0.26.2: DCN Escape Sequence RCE
CVE-2022-41322 7.8 - High - September 23, 2022

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

Output Sanitization

The Graphics Protocol feature in graphics.c in kitty before 0.19.3
CVE-2020-35605 9.8 - Critical - December 21, 2020

The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Kovidgoyal Kitty or by Kovidgoyal? Click the Watch button to subscribe.

Kovidgoyal
Vendor

subscribe