Symlink Traversal Vulnerability in Kitty Terminal Emulator
CVE-2026-80430

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-80430?

The vulnerability arises from improper handling of symlink targets in the drag and drop protocol of the Kitty terminal emulator. Specifically, a flaw in the method 'subdir_data_for_drag()' allows an attacker to create files and directories outside the intended staging directory. This happens when the system follows a symlink pointing to an arbitrary absolute path, resulting in unauthorized file creation at any writable location by the user running Kitty. The vulnerability is exacerbated by insufficient validation of symlink targets, making it essential for users to upgrade to version 0.49.0 or later to mitigate the risk.

Affected Version(s)

kitty 0.47.0 < 0.49.0

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DarĂ­o Rivas Quero
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Kovid Goyal
.