Skip to content
Multiple Vulnerabilities in Kitty Terminal Emulator Expose Users to Code Execution Risks

Multiple Vulnerabilities in Kitty Terminal Emulator Expose Users to Code Execution Risks

First seen 16 Sep 2026, 07:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 07:22 UTC
  • Kitty terminal emulator has multiple critical vulnerabilities affecting Ubuntu 26.04 LTS.
  • CVE-2026-42850 and CVE-2026-42851 allow remote code execution with user privileges.
  • Users should update to the latest package versions to mitigate these vulnerabilities.

A series of vulnerabilities have been discovered in the kitty terminal emulator, affecting Ubuntu 26.04 LTS. These vulnerabilities include improper handling of terminal escape sequences, remote edit requests, and file transmission protocols, allowing attackers to execute arbitrary commands and overwrite files. Specifically, CVE-2026-42850 and CVE-2026-42851 allow remote code execution, while CVE-2026-54055 enables local file overwriting. CVE-2026-54057 also poses a risk through unsanitized color query responses. The vulnerabilities were reported by researchers Thai Son Dinh and Nguyen Huy Vu Dung and were published on June 12, 2026. Users are advised to update their systems to mitigate these risks. The issues are currently not reported to be actively exploited in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-12
Multiple CVEs published
CVE-2026-42850, CVE-2026-42851, CVE-2026-54055, and CVE-2026-54057 were published, detailing vulnerabilities in the kitty terminal emulator.
Ubuntu
2026-06-12
CVE-2026-54057 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-12
CVE-2026-42850 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-12
CVE-2026-54055 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-12
CVE-2026-42851 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
Ubuntu Security Notice USN-8763-1 released
Ubuntu released a security notice detailing vulnerabilities in the kitty terminal emulator and recommended updates for affected users.
Ubuntu
2026-09-16
Linux Security Advisory published
Linuxsecurity.com published an advisory on the vulnerabilities in kitty, emphasizing the need for immediate updates.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-42850 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed