Use After Free Vulnerability in Kitty Terminal Emulator
CVE-2026-95834

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-95834?

The vulnerability in the Kitty terminal emulator arises from an improper handling of pointers within the drag and drop protocol. An attacker can exploit this flaw, which occurs when the terminal processes freed heap memory incorrectly. Specifically, the function 'drag_remote_file_data()' retains a reference to a pointer that was freed during its operations, leading to potential reads and writes to invalid memory locations. This behavior, if triggered, can cause unpredictable results and stability issues within the terminal process, making it a critical vector for exploitation in environments running the Kitty application.

Affected Version(s)

kitty 0.47.0 < 0.49.0

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Machado Tavares
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Kovid Goyal
.