Executive brief
Kitty, a popular cross-platform terminal emulator, contains a vulnerability in its drag-and-drop feature when used over remote connections like SSH. A malicious source could trick the terminal into overwriting or clearing files on the user's local computer that the user has permission to modify. This could lead to data loss or the corruption of important configuration files if a user drags content from a malicious remote source into their terminal.
Technical details
A vulnerability exists in the `kitten dnd` component of Kitty (specifically `kittens/dnd/drop.go` and `tools/utils/file_at_fd.go`) due to improper link resolution. On case-sensitive filesystems, the remote drag-and-drop staging process fails to de-duplicate remote basenames. An attacker can provide a `text/uri-list` containing a symlink followed by a regular file with the same name. Because `utils.CreateAt()` uses `openat()` with `O_CREAT|O_TRUNC` but lacks `O_NOFOLLOW`, the terminal follows the previously created symlink and writes the file content to the symlink's target outside the staging directory. This occurs before the final user confirmation prompt, rendering the `--confirm-drop-overwrite` protection ineffective. The issue is fixed in version 0.47.2.
Affected products
- kovidgoyal kitty 0.47.0, 0.47.1
Timeline
- 2026-06-08: advisory: Vendor advisory published on GitHub
- 2026-06-12: disclosed: CVE published to NVD
- 2026-06-12: patched: Version 0.47.2 released to address the issue