CVE-2026-42851: @kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with cat, a log line, an email body rendered in less, an issue body in a TUI, etc. — can cause kitty to execute attacker-supplied Python inside the running kitty process, with the user's full privileges. There is no approval prompt, no remote-control permission requirement, no shell-integration interaction, no clipboard touch, and no editor interaction. Version 0.47.0 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kittyto a version that resolves this vulnerability.Fixed in 0.47.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42851?
The severity of CVE-2026-42851 is rated as high with a score of 7.8.
What is the risk associated with CVE-2026-42851?
CVE-2026-42851 has a risk score of 68, indicating significant potential impact.
How do I fix CVE-2026-42851?
To fix CVE-2026-42851, you should upgrade to kitty version 0.47.0 or later.
What type of vulnerability is CVE-2026-42851?
CVE-2026-42851 is classified as a code injection vulnerability that allows unauthenticated in-process remote code execution.
Which versions of kitty are affected by CVE-2026-42851?
CVE-2026-42851 affects all versions of the kitty terminal prior to 0.47.0.