PT-2026-41985 · Kitty · Kitty
Published
2026-05-19
·
Updated
2026-05-24
·
CVE-2026-33633
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kitty versions prior to 0.47.0
Description
A heap buffer overflow exists in the
load image data() function. This occurs when a process writes to the terminal's stdin using a single APC graphics protocol command with a PNG format declaration (f=100) where the payload exceeds twice the initial buffer capacity. An attacker can control both the length and content of the overflow, which can lead to an immediate crash (Denial of Service) or potentially result in Remote Code Execution (RCE), where an attacker executes arbitrary code on the target machine.Recommendations
Update to version 0.47.0.
Exploit
Fix
DoS
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kitty