VYPR
Medium severity4.1NVD Advisory· Published Apr 20, 2025· Updated Jun 17, 2026

CVE-2025-43929

CVE-2025-43929

Description

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • KiTTY/KiTTYllm-fuzzy
    Range: <0.41.0
  • Kovidgoyal/Kittyv52 versions
    0+ 1 more
    • (no CPE)range: 0
    • cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:*range: <0.41.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.