# CVE-2026-72913

## Summary

- **CVE ID:** CVE-2026-72913
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-77, CWE-93, CWE-150
- **Published:** Aug 10, 2026
- **Last Modified:** Aug 11, 2026

## Description

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.

## Affected Products

- kovidgoyal — kitty (< 0.48.2)

## References

- [CNA](https://github.com/kovidgoyal/kitty/security/advisories/GHSA-ccp2-q4v6-rw94)
- [CNA](https://github.com/kovidgoyal/kitty/commit/9dca948e9bec3c926ab3370f2cd10f9b9b10821f)
- [CNA](https://github.com/kovidgoyal/kitty/releases/tag/v0.48.2)
- [CNA](https://sw.kovidgoyal.net/kitty/changelog/#id1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 4.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._