Skip to content
USN-8763-1: kitty vulnerabilities

USN-8763-1: kitty vulnerabilities

Ubuntu September 15, 2026

It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 ) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 ) Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 ) It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute...

It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 )

It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 )

Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 )

It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute...

It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 ) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 ) Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 ) It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-54057 )

It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 )

It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 )

Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 )

It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-54057 )

In general, a standard system update will make all the necessary changes.

The problem can be corrected by updating your system to the following package versions:

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.