Critical severity9.8NVD Advisory· Published Dec 21, 2020· Updated Jun 17, 2026
CVE-2020-35605
CVE-2020-35605
Description
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- kitty/kittydescription
- osv-coords2 versionspkg:rpm/opensuse/kitty&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/kitty&distro=openSUSE%20Tumbleweed
< 0.16.0-lp152.2.3.1+ 1 more
- (no CPE)range: < 0.16.0-lp152.2.3.1
- (no CPE)range: < 0.21.2-1.2
Patches
Vulnerability mechanics
References
3- github.com/kovidgoyal/kitty/commit/82c137878c2b99100a3cdc1c0f0efea069313901nvdPatchThird Party Advisory
- github.com/kovidgoyal/kitty/issues/3128nvdExploitIssue TrackingThird Party Advisory
- www.debian.org/security/2020/dsa-4819nvdThird Party Advisory
News mentions
0No linked articles in our index yet.