Rapid7

vulnerability

Gentoo Linux: CVE-2022-41322: Kitty: Arbitrary Code Execution

Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Sep 23, 2022
Added
Sep 30, 2022
Modified
Mar 31, 2026

Description

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

Solution

gentoo-linux-upgrade-x11-terms-kitty
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.