VulnSea

Kovid Goyal has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 5.8 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.8
Publish → KEV
—
Last 90 days
6 prev 0

Products

  • kitty 6
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Kovid Goyal vulnerabilities

CVEs affecting Kovid Goyal, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-95835Medium· 5.6
2d ago

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-80432Medium· 6.0
2d ago

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-95834Medium· 4.6
2d ago

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_…

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-80430Medium· 4.6
2d ago

Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the st…

Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the st…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-80431Medium· 6.8
2d ago

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command…

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command…

▾ SunlitKovid Goyal · kittyvia NVD
CVE-2026-95832Critical· 9.3
2d ago

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in…

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in…

▾ MidnightKovid Goyal · kittyvia NVD
Kovid Goyal vulnerabilities (CVEs) · VulnSea