CVE-2022-41322

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/09/2022
Last modified:
01/06/2025

Description

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kitty_project:kitty:*:*:*:*:*:*:*:* 0.26.2 (excluding)
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*