PatchSiren

Kovid Goyal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Kovid Goyal CVE published 2026-09-25

CVE-2026-80430

A vulnerability in kitty's drag and drop protocol allows a program writing to the terminal to create files and directories outside the staging directory. This issue exists in kitty versions from 0.47.0 before 0.49.0. The vulnerability arises from improper link resolution before file access, enabling an attacker to create files and directories at arbitrary paths writable by the user running kitty. Entry na [truncated]