PT-2026-98932 · Kitty · Kitty

·

CVE-2026-95835

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.6

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions kitty versions 0.25.0 through 0.48.9
Description Missing authorization in the askpass escape code handler allows a local user to obtain text typed into a prompt displayed by the terminal. The handle remote askpass() function in kitty/window.py opens a POSIX shared memory object named in the escape code, parses a prompt definition, and writes the user's answer back into an object of the same name without verifying ownership or permissions. An attacker can create a shared memory object, trigger the victim's terminal to render a custom prompt (such as a masked password prompt) via a device control string, and subsequently read the typed secret. Additionally, the prompt text is passed to the display without control character sanitisation, allowing it to overwrite the warning line printed by the software.
Recommendations Update kitty to version 0.49.0 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95835

Affected Products

Kitty