PT-2026-41985 · Kitty · Kitty

Published

2026-05-19

·

Updated

2026-05-24

·

CVE-2026-33633

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kitty versions prior to 0.47.0
Description A heap buffer overflow exists in the load image data() function. This occurs when a process writes to the terminal's stdin using a single APC graphics protocol command with a PNG format declaration (f=100) where the payload exceeds twice the initial buffer capacity. An attacker can control both the length and content of the overflow, which can lead to an immediate crash (Denial of Service) or potentially result in Remote Code Execution (RCE), where an attacker executes arbitrary code on the target machine.
Recommendations Update to version 0.47.0.

Exploit

Fix

DoS

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33633

Affected Products

Kitty