open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
References
Link | Resource |
---|---|
https://ghostwriter.kde.org/documentation/#links | Product |
https://github.com/0xBenCantCode/CVE-2025-43929 | Exploit |
https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 | Patch |
https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0 | Patch |
https://hitman.services/cve-2025-43929/ | Exploit Third Party Advisory |
Configurations
History
24 Apr 2025, 15:46
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Kovidgoyal kitty
Kovidgoyal |
|
References | () https://ghostwriter.kde.org/documentation/#links - Product | |
References | () https://github.com/0xBenCantCode/CVE-2025-43929 - Exploit | |
References | () https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 - Patch | |
References | () https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0 - Patch | |
References | () https://hitman.services/cve-2025-43929/ - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:* |
20 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Apr 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-20 03:15
Updated : 2025-04-24 15:46
NVD link : CVE-2025-43929
Mitre link : CVE-2025-43929
CVE.ORG link : CVE-2025-43929
JSON object : View
Products Affected
kovidgoyal
- kitty
CWE
CWE-346
Origin Validation Error