CVE-2026-54056: Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop staging

Published Jun 12, 2026
·
Updated

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, kitten dnd can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the local kitty user. Remote text/uri-list drops are staged in a temporary directory, but on case-sensitive filesystems duplicate remote basenames are not de-duplicated. An attacker can first create a staged symlink and then send a same-name regular-file entry. The regular-file write uses utils.CreateAt() / openat(ORDWR|OCREAT|OTRUNC) without ONOFOLLOW, so it follows the attacker-created symlink and writes outside the staging directory before final overwrite confirmation runs. This appears related in class to the file-transfer symlink advisory, but it is a different bug: it affects kitten dnd remote drag-and-drop staging, uses different vulnerable code (kittens/dnd/drop.go and tools/utils/fileatfd.go), and reproduces on commit 4aa4a5c0567a92553a8c20a88a4352da637fca5d, after the file-transfer ONOFOLLOW fix. Version 0.47.2 patches the issue.

Affected Software

2 affected components
Kitty Kitty>=0.47.0<=0.47.1
Kovidgoyal Kitty>=0.47.0<0.47.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kitty to a version that resolves this vulnerability.

    Fixed in 0.47.2

Event History

Jun 12, 2026
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-54056?

The severity of CVE-2026-54056 is rated as high with a score of 7.6.

2

How do I fix CVE-2026-54056?

To fix CVE-2026-54056, update to the latest version of Kitty that addresses this vulnerability.

3

What type of vulnerability is CVE-2026-54056?

CVE-2026-54056 is an arbitrary file overwrite vulnerability that can be exploited via symlinks in the drag-and-drop functionality.

4

What versions of Kitty are affected by CVE-2026-54056?

CVE-2026-54056 affects Kitty versions 0.47.0 and 0.47.1.

5

What impact does CVE-2026-54056 have on users?

CVE-2026-54056 allows a malicious remote source to overwrite or truncate arbitrary files that the local Kitty user can write to.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203