๐Ÿ” CVE Alert

CVE-2026-72913

UNKNOWN 0.0

Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.

CWE CWE-77 CWE-93 CWE-150
Vendor kovidgoyal
Product kitty
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for kovidgoyal kitty

Be the first to know when new unknown vulnerabilities affecting kovidgoyal kitty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kovidgoyal / kitty
< 0.48.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kovidgoyal/kitty/security/advisories/GHSA-ccp2-q4v6-rw94 github.com: https://github.com/kovidgoyal/kitty/commit/9dca948e9bec3c926ab3370f2cd10f9b9b10821f github.com: https://github.com/kovidgoyal/kitty/releases/tag/v0.48.2 sw.kovidgoyal.net: https://sw.kovidgoyal.net/kitty/changelog/#id1