PT-2026-69981 · Kitty · Kitty

CVE-2026-72913

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kitty versions prior to 0.48.2
Description In the kitty/window.py file, the @kitty-echo and @kitty-ssh DCS handlers write unauthenticated data to the child shell's stdin. The handle remote echo() function accepts printable shell command characters, and the handle remote ssh() function calls get ssh data() in kittens/ssh/utils.py, which emits a newline. By chaining these handlers, an attacker can execute arbitrary commands when a user displays untrusted terminal data.
Recommendations Update to version 0.48.2.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72913
GHSA-CCP2-Q4V6-RW94

Affected Products

Kitty