USN-8763-1: kitty vulnerabilities

Publication date

15 September 2026

Overview

Several security issues were fixed in kitty.


Packages

  • kitty - fast, featureful, GPU based terminal emulator

Details

It was discovered that kitty incorrectly escaped error messages when
handling specially crafted terminal escape sequences. A remote attacker
could possibly use this issue to execute arbitrary commands.
(CVE-2026-42850)

It was discovered that kitty incorrectly handled remote edit requests in
terminal output. An attacker could possibly use this issue to execute
arbitrary code with the user's privileges.
(CVE-2026-42851)

Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly
handled destination paths in its file transmission protocol. A local
attacker could possibly use this issue to overwrite arbitrary files with
the user's privileges.
(CVE-2026-54055)

It was discovered that kitty incorrectly sanitized responses to color
queries. An attacker could possibly use this issue to execute...

It was discovered that kitty incorrectly escaped error messages when
handling specially crafted terminal escape sequences. A remote attacker
could possibly use this issue to execute arbitrary commands.
(CVE-2026-42850)

It was discovered that kitty incorrectly handled remote edit requests in
terminal output. An attacker could possibly use this issue to execute
arbitrary code with the user's privileges.
(CVE-2026-42851)

Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly
handled destination paths in its file transmission protocol. A local
attacker could possibly use this issue to overwrite arbitrary files with
the user's privileges.
(CVE-2026-54055)

It was discovered that kitty incorrectly sanitized responses to color
queries. An attacker could possibly use this issue to execute arbitrary
commands with the user's privileges. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54057)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute kitty –  0.45.0-1ubuntu0.1~esm2  
24.04 LTS noble kitty –  0.32.2-1ubuntu0.4+esm2  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›