USN-8763-1

Source
https://ubuntu.com/security/notices/USN-8763-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8763-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8763-1
Upstream
Related
Published
2026-09-15T13:31:45Z
Modified
2026-09-16T02:57:27Z
Summary
kitty vulnerabilities
Details

It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-42850)

It was discovered that kitty incorrectly handled remote edit requests in terminal output. An attacker could possibly use this issue to execute arbitrary code with the user's privileges. (CVE-2026-42851)

Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly handled destination paths in its file transmission protocol. A local attacker could possibly use this issue to overwrite arbitrary files with the user's privileges. (CVE-2026-54055)

It was discovered that kitty incorrectly sanitized responses to color queries. An attacker could possibly use this issue to execute arbitrary commands with the user's privileges. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54057)

References

Affected packages

Ubuntu:Pro:24.04:LTS / kitty

Package

Name
kitty
Purl
pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.32.2-1ubuntu0.4+esm2

Affected versions

0.*
0.26.5-3ubuntu2
0.26.5-5ubuntu1
0.31.0-3
0.31.0-4
0.32.2-1
0.32.2-1build2
0.32.2-1build3
0.32.2-1ubuntu0.1
0.32.2-1ubuntu0.2
0.32.2-1ubuntu0.3
0.32.2-1ubuntu0.4
0.32.2-1ubuntu0.4+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "kitty",
            "binary_version": "0.32.2-1ubuntu0.4+esm2"
        },
        {
            "binary_name": "kitty-shell-integration",
            "binary_version": "0.32.2-1ubuntu0.4+esm2"
        },
        {
            "binary_name": "kitty-terminfo",
            "binary_version": "0.32.2-1ubuntu0.4+esm2"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-42850",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-42851",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-54055",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8763-1.json"

Ubuntu:Pro:26.04:LTS / kitty

Package

Name
kitty
Purl
pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fresolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.45.0-1ubuntu0.1~esm2

Affected versions

0.*
0.41.1-2
0.43.1-1
0.44.0-1
0.45.0-1
0.45.0-1build1
0.45.0-1ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "kitty",
            "binary_version": "0.45.0-1ubuntu0.1~esm2"
        },
        {
            "binary_name": "kitty-shell-integration",
            "binary_version": "0.45.0-1ubuntu0.1~esm2"
        },
        {
            "binary_name": "kitty-terminfo",
            "binary_version": "0.45.0-1ubuntu0.1~esm2"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2026-42850",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-42851",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-54055",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-54057",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:26.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8763-1.json"