Symlink Traversal Vulnerability in Kitty Terminal Emulator
CVE-2026-80430
4.6MEDIUM
What is CVE-2026-80430?
The vulnerability arises from improper handling of symlink targets in the drag and drop protocol of the Kitty terminal emulator. Specifically, a flaw in the method 'subdir_data_for_drag()' allows an attacker to create files and directories outside the intended staging directory. This happens when the system follows a symlink pointing to an arbitrary absolute path, resulting in unauthorized file creation at any writable location by the user running Kitty. The vulnerability is exacerbated by insufficient validation of symlink targets, making it essential for users to upgrade to version 0.49.0 or later to mitigate the risk.
Affected Version(s)
kitty 0.47.0 < 0.49.0
References
CVSS V4
Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
DarĂo Rivas Quero
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Kovid Goyal
