Kovidgoyal maintains kitty, a terminal emulator with a focused but prominent user base in development and systems-administration environments. The observed vulnerability surface concentrates on memory-safety issues—including heap-based buffer overflows, integer overflows, and out-of-bounds reads—alongside input-validation and origin-checking weaknesses characteristic of a graphics-intensive client application. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kovidgoyal over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33642CRITICAL Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offs | May 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-33633HIGH Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal' | May 19, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-42850HIGH Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will mak | Jun 12, 2026 | 8.8 | 31 | NO | NO |
CVE-2020-35605CRITICAL The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be include | Dec 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-42851HIGH Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat | Jun 12, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-54057HIGH Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into t | Jun 12, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-54056HIGH Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files | Jun 12, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-54055MEDIUM Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child pro | Jun 12, 2026 | 5.0 | 22 | NO | NO |
CVE-2025-43929HIGH open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a docum | Apr 20, 2025 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kovidgoyal.
Media articles that mention a CVE ID that affects a product developed by Kovidgoyal — matched by CVE ID, not by vendor name.