CVE-2026-42851·Python vulnerability
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to execute attacker-supplied Python inside the running kitty process, with the user's full privileges. There is no approval prompt, no remote-control permission requirement, no shell-integration interaction, no clipboard touch, and no editor interaction. Version 0.47.0 fixes the issue.
- Severity
- high
- Software
- Python
- Fixed in
- 0.47.0
- Published
- 2026-06-12
Affected versions
Until: 0.47.0
Fixed in: 0.47.0
How to fix this CVE
Update Python to version 0.47.0 or later to eliminate the risk of arbitrary code execution through terminal input. This vulnerability allows malicious actors to inject and execute Python code within the kitty terminal process when data is written to the terminal, requiring immediate patching across all affected systems.
sudo dnf upgrade python3Defensia detects this vulnerability
How to check if you are affected
- Check the installed Python version: python3 --version
- Verify kitty terminal is installed and note its version: kitty --version
- Review shell history and terminal logs for suspicious Python module imports or exec() calls: grep -r 'exec\|__import__\|eval' ~/.local/share/kitty/ 2>/dev/null
- Confirm the patched version is active: python3 -c 'import sys; print(sys.version)' and verify kitty version is 0.47.0 or higher
FAQ
What is CVE-2026-42851?
This is a critical code execution vulnerability in kitty terminal that allows any program with write access to the terminal (remote SSH sessions, downloaded files, log viewers) to execute arbitrary Python code within the kitty process with the user's full privileges, without any user confirmation or permission check.
Is CVE-2026-42851 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits are available, but the attack surface is broad and exploitation requires minimal technical sophistication.
What versions of Python are affected by CVE-2026-42851?
All versions of kitty prior to 0.47.0 are affected; Python itself is not the vulnerable component—kitty's terminal emulator is the affected software that processes terminal escape sequences maliciously.
How do I check if my server is vulnerable to CVE-2026-42851?
Run `kitty --version` to check the terminal version. If it reports a version earlier than 0.47.0, the system is vulnerable and must be updated immediately.
Does Defensia detect CVE-2026-42851?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If kitty terminal is installed on a monitored server, CVE-2026-42851 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-42851. Free for 1 server.
Get started free