open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
References
| Link | Resource |
|---|---|
| https://ghostwriter.kde.org/documentation/#links | Product |
| https://github.com/0xBenCantCode/CVE-2025-43929 | Exploit |
| https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 | Patch |
| https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0 | Patch |
| https://hitman.services/cve-2025-43929/ | Exploit Third Party Advisory |
Configurations
History
24 Apr 2025, 15:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:kovidgoyal:kitty:*:*:*:*:*:*:*:* | |
| First Time |
Kovidgoyal kitty
Kovidgoyal |
|
| References | () https://ghostwriter.kde.org/documentation/#links - Product | |
| References | () https://github.com/0xBenCantCode/CVE-2025-43929 - Exploit | |
| References | () https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35 - Patch | |
| References | () https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0 - Patch | |
| References | () https://hitman.services/cve-2025-43929/ - Exploit, Third Party Advisory | |
| Summary |
|
20 Apr 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Apr 2025, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-20 03:15
Updated : 2025-04-24 15:46
NVD link : CVE-2025-43929
Mitre link : CVE-2025-43929
CVE.ORG link : CVE-2025-43929
JSON object : View
Products Affected
kovidgoyal
- kitty
CWE
CWE-346
Origin Validation Error
