open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
{ "binaries": [ { "binary_version": "0.32.2-1ubuntu0.4", "binary_name": "kitty" }, { "binary_version": "0.32.2-1ubuntu0.4", "binary_name": "kitty-shell-integration" }, { "binary_version": "0.32.2-1ubuntu0.4", "binary_name": "kitty-terminfo" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-43929.json"
{ "binaries": [ { "binary_version": "0.41.1-2", "binary_name": "kitty" }, { "binary_version": "0.41.1-2", "binary_name": "kitty-shell-integration" }, { "binary_version": "0.41.1-2", "binary_name": "kitty-terminfo" } ] }
{ "binaries": [ { "binary_version": "0.39.1-1", "binary_name": "kitty" }, { "binary_version": "0.39.1-1", "binary_name": "kitty-shell-integration" }, { "binary_version": "0.39.1-1", "binary_name": "kitty-terminfo" } ] }