Home
MEDIUM: 4.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 0.41.0
affected
Description
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
Problem types
CWE-346 Origin Validation Error
Product status
Any version before 0.41.0
References
github.com/...ommit/ce5cfdd9caf44c538af800a07162e1f49bd53c35
github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0
ghostwriter.kde.org/documentation/
hitman.services/cve-2025-43929/
github.com/0xBenCantCode/CVE-2025-43929