CVE-2025-43929

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
Configurations

Configuration 1 (hide)

cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:*

History

24 Apr 2025, 15:46

Type Values Removed Values Added
Summary
  • (es) open_actions.py en kitty anterior a 0.41.0 no solicita confirmación del usuario antes de ejecutar un archivo ejecutable local que puede haber sido vinculado desde un documento no confiable (por ejemplo, un documento abierto en KDE ghostwriter).
First Time Kovidgoyal kitty
Kovidgoyal
References () https://ghostwriter.kde.org/documentation/#links - () https://ghostwriter.kde.org/documentation/#links - Product
References () https://github.com/0xBenCantCode/CVE-2025-43929 - () https://github.com/0xBenCantCode/CVE-2025-43929 - Exploit
References () https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 - () https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 - Patch
References () https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0 - () https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0 - Patch
References () https://hitman.services/cve-2025-43929/ - () https://hitman.services/cve-2025-43929/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:*

20 Apr 2025, 14:15

Type Values Removed Values Added
References
  • () https://github.com/0xBenCantCode/CVE-2025-43929 -
  • () https://hitman.services/cve-2025-43929/ -

20 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-20 03:15

Updated : 2025-04-24 15:46


NVD link : CVE-2025-43929

Mitre link : CVE-2025-43929

CVE.ORG link : CVE-2025-43929


JSON object : View

Products Affected

kovidgoyal

  • kitty
CWE
CWE-346

Origin Validation Error