Command Injection Vulnerability in Kitty Terminal by Kovid Goyal
CVE-2026-72913
7.3HIGH
What is CVE-2026-72913?
Kitty Terminal is susceptible to a command injection vulnerability that allows attackers to execute arbitrary commands through unauthenticated data sent to the child shell's stdin. Prior to version 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers could be exploited when untrusted terminal data was displayed. This vulnerability is addressed in version 0.48.2, emphasizing the need for users to update their installations to mitigate the risk of unauthorized command execution.
Affected Version(s)
kitty < 0.48.2
