Two vulnerabilities in the kitty terminal emulator (CVE-2026-33633 and CVE-2026-33642) allow an attacker who can write to the terminal's input or send specific escape sequences to cause a denial of service or potentially execute arbitrary code. The article does not specify affected or fixed version numbers, nor does it provide a CVSS score or workaround.
It was discovered that kitty incorrectly handled certain image data. An attacker able to write to the terminal's input could possibly use this issue to cause kitty to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-33633) It was discovered that kitty incorrectly handled certain graphics commands. An attacker able to write escape sequences to a kitty terminal could possibly use this issue to cause kitty to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-33642)