Home

Description

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

PUBLISHED Reserved 2025-04-20 | Published 2025-04-20 | Updated 2025-04-21 | Assigner mitre




MEDIUM: 4.1CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-346 Origin Validation Error

Product status

Default status
unaffected

Any version before 0.41.0
affected

References

github.com/...ommit/ce5cfdd9caf44c538af800a07162e1f49bd53c35

github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0

ghostwriter.kde.org/documentation/

hitman.services/cve-2025-43929/

github.com/0xBenCantCode/CVE-2025-43929

cve.org (CVE-2025-43929)

nvd.nist.gov (CVE-2025-43929)

Download JSON