CVE-2026-72913: Kovidgoyal Kitty
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.
Affected products
- Kovidgoyal Kitty: before 0.48.2 (fixed in 0.48.2)
Published 2026-08-10. Last modified 2026-09-09.