Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kovidgoyal
Kovidgoyal kitty |
|
| Vendors & Products |
Kovidgoyal
Kovidgoyal kitty |
Mon, 10 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2. | |
| Title | Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences | |
| Weaknesses | CWE-150 CWE-77 CWE-93 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T15:59:44.886Z
Reserved: 2026-08-10T17:57:26.143Z
Link: CVE-2026-72913
Updated: 2026-08-11T15:57:43.820Z
Status : Received
Published: 2026-08-10T21:17:26.297
Modified: 2026-08-11T16:17:37.477
Link: CVE-2026-72913
No data.
OpenCVE Enrichment
Updated: 2026-08-11T02:30:17Z