CVE-2022-41322
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.8epss 0.5%
probabilidad de explotación
0.5%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/aReferencias
https://bugs.gentoo.org/868543https://github.com/kovidgoyal/kitty/commit/f05783e64d5fa62e1aed603e8d69aced5e49824fhttps://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2https://lists.debian.org/debian-lts-announce/2025/06/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RRNAPU33PHEH64P77YL3AJO6CTZGHTX/https://security.gentoo.org/glsa/202209-22https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes