2026-09-08 22:32 UTC
That does not allow remote code execution. An attacker still needs a vector like an SSH session to be able to control kitty. And at that point, if they already have a shell session, they don’t need kitty to do damage.
Replies (1)
-
@starblursd@lemmy.zip 2026-09-08 22:48
It actually also allows other programs to execute code through Kitty, example if you cat a file that has escapes in it. It would allow Kitty to execute that code when you never intended it… But like why does kitty even have that as a feature? But they’ve since updated the config to be set to socket only instead of yes