Executive brief
Kitty is a popular cross-platform terminal emulator. A security flaw in its file transmission protocol allows a malicious program running inside the terminal to trick the user into overwriting sensitive files. While the user is prompted to approve a file transfer, an attacker can exploit a timing window to redirect that transfer to a different, unapproved file (like configuration or SSH keys), potentially leading to a full system compromise under the user's account.
Technical details
A TOCTOU race condition exists in `kitty/file_transmission.py` within the `DestFile` class. The application performs a symlink check using `os.stat` during initialization but fails to use the `O_NOFOLLOW` flag during the subsequent `os.open` call in the `write_data()` method. A malicious child process can create a symlink at the target path after the initial check but before the file is opened. This allows the process to bypass the user's file transfer confirmation and overwrite arbitrary files that the user has write permissions for. The vulnerability is addressed in version 0.47.2 by ensuring symlinks are not followed during the open operation.
Affected products
- kovidgoyal Kitty < 0.47.2
Timeline
- 2026-06-08: advisory: GitHub security advisory published by maintainer
- 2026-06-12: disclosed: CVE published to NVD
- 2026-06-12: patched: Fixed in version 0.47.2