open_actions.py in kitty before 0.41.0 does not ask for...
Moderate severity
Unreviewed
Published
Apr 20, 2025
to the GitHub Advisory Database
•
Updated Apr 20, 2025
Description
Published by the National Vulnerability Database
Apr 20, 2025
Published to the GitHub Advisory Database
Apr 20, 2025
Last updated
Apr 20, 2025
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
References