Skip to content
Ubuntu 26.04 LTS Kitty Important Arbitrary Code Execution Vuln 8763-1

Ubuntu 26.04 LTS Kitty Important Arbitrary Code Execution Vuln 8763-1

Linuxsecurity September 16, 2026

Artifactory Alert: Chained flaws let attackers gain admin control. Check your version now ×

Several security issues were fixed in kitty. Software Description: - kitty: fast, featureful, GPU based terminal emulator Details: It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-42850) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. (CVE-2026-42851) Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. (CVE-2026-54055) It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This ... Read the Full Advisory

Several security issues were fixed in kitty.

Software Description:

- kitty: fast, featureful, GPU based terminal emulator

It was discovered that kitty incorrectly escaped error messages when

handling specially crafted terminal escape sequences. A remote attacker

could possibly use this issue to execute arbitrary commands.

It was discovered that kitty incorrectly handled remote edit requests in

terminal output. An attacker could possibly use this issue to execute

arbitrary code with the user's privileges.

Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly

handled destination paths in its file transmission protocol. A local

attacker could possibly use this issue to overwrite arbitrary files with

the user's privileges.

It was discovered that kitty incorrectly sanitized responses to color

queries. An attacker could possibly use this issue to execute arbitrary

commands with the user's privileges. This ...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS kitty 0.45.0-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 24.04 LTS kitty 0.32.2-1ubuntu0.4+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2026-42850, CVE-2026-42851, CVE-2026-54055, CVE-2026-54057

Ubuntu Security Notice USN-8763-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases