CVE-2022-41322: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Affected products
- Fedoraproject Fedora: version 36 only; version 37 only
- Kitty Project Kitty: before 0.26.2 (fixed in 0.26.2)
Published 2022-09-23. Last modified 2026-06-17.