
This isn't unique to Kitty. iTerm2's CVE-2019-9535 was a famous escape-sequence RCE. VTE, xterm, and tmux have all shipped parser bugs. Escape sequences are a 1970s spec that grew new features for 50 years — the attack surface keeps growing.
Post summary
The post highlights that iTerm2’s CVE‑2019‑9535 was an escape‑sequence RCE and that VTE, xterm, and tmux have similar parser bugs, but offers no PoC, exploit code, patch, or evidence of active exploitation.
