
Kitty through 0.48.1 can execute commands when crafted terminal data is displayed. Upgrade to 0.48.2, avoid printing raw untrusted logs/files, and use viewers that escape control sequences. https://nvd.nist.gov/vuln/detail/CVE-2026-72913
Post summary
The advisory highlights that Kitty up to version 0.48.1 is vulnerable to command execution via crafted terminal data and advises users to upgrade to 0.48.2 and sanitize untrusted logs.
