Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-43929

Опубликовано: 20 апр. 2025
Источник: nvd
CVSS3: 4.1
CVSS3: 7.8
EPSS Низкий

Описание

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:*
Версия до 0.41.0 (исключая)

EPSS

Процентиль: 1%
0.00011
Низкий

4.1 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-346
CWE-346

Связанные уязвимости

CVSS3: 4.1
ubuntu
2 месяца назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVSS3: 4.1
debian
2 месяца назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmat ...

CVSS3: 4.1
github
2 месяца назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

EPSS

Процентиль: 1%
0.00011
Низкий

4.1 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-346
CWE-346