VYPR
High severity7.8NVD Advisory· Published Sep 23, 2022· Updated Jun 17, 2026

CVE-2022-41322

CVE-2022-41322

Description

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:kitty_project:kitty:*:*:*:*:*:*:*:*
    Range: <0.26.2
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • Kitty/Kittydescription
  • Kovidgoyal/Kittyllm-fuzzy
    Range: <0.26.2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.