VYPR
High severity7.8NVD Advisory· Published Feb 9, 2024· Updated Jun 17, 2026

CVE-2024-23749

CVE-2024-23749

Description

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • KiTTY/KiTTYdescription
  • KiTTY/KiTTYllm-fuzzy
    Range: <=0.76.1.13

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.