Total vulnerabilities in the database
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Software | From | Fixed in |
---|---|---|
kitty_project / kitty | - | 0.26.2 |
fedoraproject / fedora | 36 | 36.x |
fedoraproject / fedora | 37 | 37.x |