Vulnerabilidades en Kovid Goyal
6 resultadosAnálisis Vexday
Kovid Goyal apresenta footprint reduzido com apenas 3 CVEs, nenhuma sob exploração ativa conhecida. Porém, as vulnerabilidades são recentes (todas publicadas nos últimos 90 dias) com uma crítica em CVSS, e concentram-se em CWE-59 (symlink/hardlink issues), indicando foco em escalação de privilégio local que merece atenção em ambientes multi-usuário.
CVE-2026-95832CRITICALReflected unknown field names in the kitty colour control escape code allow command execution in the user's shellEPSS —CVE-2026-80431MEDIUMOut-of-bounds write in the kitty text sizing protocol allows termination of the terminal processEPSS —CVE-2026-95835MEDIUMMissing ownership check on the shared memory object named by the kitty askpass escape codeEPSS —CVE-2026-80432MEDIUMMissing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a dropEPSS —CVE-2026-95834MEDIUMUse after free in the kitty drag and drop protocol when a drag source item is aborted mid-transferEPSS —CVE-2026-80430MEDIUMImproper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directoryEPSS —