Kitty
Vendor:
First CVE: Dec 21, 2020 · Active for 5 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kitty over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2020
5 years ago
Most Recent CVE
Jun 12, 2026
42 days ago
CVE Severity & Scoring
Kitty9 CVEs
11%
67%
22%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (44.4%)
Network5 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33642CRITICAL Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offs | May 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-33633HIGH Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal' | May 19, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-42850HIGH Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will mak | Jun 12, 2026 | 8.8 | 31 | NO | NO |
CVE-2020-35605CRITICAL The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be include | Dec 21, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-42851HIGH Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat | Jun 12, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-54057HIGH Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into t | Jun 12, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-54056HIGH Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files | Jun 12, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-54055MEDIUM Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child pro | Jun 12, 2026 | 5.0 | 22 | NO | NO |
CVE-2025-43929HIGH open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a docum | Apr 20, 2025 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Kitty
Top CWEs
Versions
No cataloged versions.