
CVE-2026-33642 Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on co… https://www.cve.org/CVERecord?id=CVE-2026-33642
Post summary
The post discloses a bounds-validation flaw in Kitty terminal’s graphics.c, provides some technical detail about the vulnerable function but no PoC, exploit code, or patch information, and does not indicate active exploitation or a false positive.


