Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-72913

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.

A flaw was found in Kitty, a cross-platform GPU based terminal. This vulnerability allows an attacker to achieve arbitrary code execution by chaining specific escape sequences (@kitty-echo and @kitty-ssh) when a user displays untrusted terminal data. These sequences write unauthenticated data to the child shell's input, enabling the execution of attacker-controlled commands. This could lead to a complete compromise of the user's system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Red Hat Enterprise Linux 10gvisor-tap-vsockAffected
Red Hat Enterprise Linux 9gvisor-tap-vsockAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2513692kitty: Kitty: Arbitrary Code Execution via Chained DCS Escape Sequences

EPSS

Процентиль: 4%
0.00144
Низкий

7.8 High

CVSS3

Связанные уязвимости

ubuntu
18 дней назад

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.

nvd
18 дней назад

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.

debian
18 дней назад

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @ki ...

EPSS

Процентиль: 4%
0.00144
Низкий

7.8 High

CVSS3

Уязвимость CVE-2026-72913