PT-2026-98839 · Kitty · Kitty

·

CVE-2026-80430

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions kitty versions 0.47.0 through 0.48.x
Description Improper link resolution in the drag source staging path of the drag and drop protocol allows a program writing to the terminal to create files and directories outside the staging directory. This occurs because the subdir data for drag() function in kitty/dnd.c resolves descendants of the staged item tree by constructing a path string and opening it with safe open(path, O DIRECTORY | O RDONLY, 0) instead of walking the tree component by component. An attacker can declare two entries with the same name—first a symlink targeting an arbitrary absolute path and second a directory—causing mkdirat() to fail with EEXIST. The code ignores this failure, leading the subsequent path resolution to follow the symlink and return a directory descriptor outside the staging directory. This descriptor is then passed as the dirfd argument to add payload() and used for all subsequent create operations. While entry names are sanitized, symlink targets are not validated. Files are created with O CREAT | O WRONLY | O EXCL at mode 0644, preventing the overwriting of existing files, but directories are created with mkdirat() at mode 0755, allowing the creation of new intermediate directories at any path writable by the user running the application, provided the symlink target is an existing directory.
Recommendations Update kitty to version 0.49.0 or later.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80430

Affected Products

Kitty