PT-2026-98932 · Kitty · Kitty
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
kitty versions 0.25.0 through 0.48.9
Description
Missing authorization in the askpass escape code handler allows a local user to obtain text typed into a prompt displayed by the terminal. The
handle remote askpass() function in kitty/window.py opens a POSIX shared memory object named in the escape code, parses a prompt definition, and writes the user's answer back into an object of the same name without verifying ownership or permissions. An attacker can create a shared memory object, trigger the victim's terminal to render a custom prompt (such as a masked password prompt) via a device control string, and subsequently read the typed secret. Additionally, the prompt text is passed to the display without control character sanitisation, allowing it to overwrite the warning line printed by the software.Recommendations
Update kitty to version 0.49.0 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kitty