It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 ) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 ) Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 ) It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute...
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 )
It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 )
Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 )
It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute...
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 ) It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 ) Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 ) It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-54057 )
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. ( CVE-2026-42850 )
It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. ( CVE-2026-42851 )
Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. ( CVE-2026-54055 )
It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-54057 )
In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions:
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
