CVE-2025-43929

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 20, 2025
Updated: Apr 24, 2025
CWE ID 346

Summary

CVE-2025-43929 is a vulnerability affecting the kitty terminal emulator before version 0.41.0. This issue arises due to the open_actions.py component's failure to request user confirmation before executing local files. These files may be linked within untrusted documents such as those opened in KDE ghostwriter. Exploitation of this vulnerability could result in the execution of arbitrary code, potentially leading to significant security risks for users. It is recommended that users update their kitty terminal emulator to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Kovidgoyal Kitty

Affected Vendors

  • Kovidgoyal