PT-2026-98839 · Kitty · Kitty
CVSS v4.0
4.6
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
kitty versions 0.47.0 through 0.48.x
Description
Improper link resolution in the drag source staging path of the drag and drop protocol allows a program writing to the terminal to create files and directories outside the staging directory. This occurs because the
subdir data for drag() function in kitty/dnd.c resolves descendants of the staged item tree by constructing a path string and opening it with safe open(path, O DIRECTORY | O RDONLY, 0) instead of walking the tree component by component. An attacker can declare two entries with the same name—first a symlink targeting an arbitrary absolute path and second a directory—causing mkdirat() to fail with EEXIST. The code ignores this failure, leading the subsequent path resolution to follow the symlink and return a directory descriptor outside the staging directory. This descriptor is then passed as the dirfd argument to add payload() and used for all subsequent create operations. While entry names are sanitized, symlink targets are not validated. Files are created with O CREAT | O WRONLY | O EXCL at mode 0644, preventing the overwriting of existing files, but directories are created with mkdirat() at mode 0755, allowing the creation of new intermediate directories at any path writable by the user running the application, provided the symlink target is an existing directory.Recommendations
Update kitty to version 0.49.0 or later.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kitty