Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-41322

Disclosure Date: September 23, 2022 (last updated November 08, 2023)
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Attacker Value
Unknown

CVE-2021-33038

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration of the import. For example, sensitive information might be available on the web for an hour during a large migration from Mailman 2 to Mailman 3.
Attacker Value
Unknown

CVE-2021-25322

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions. openSUSE Factory python-HyperKitty versions prior to 1.3.4-5.1.
Attacker Value
Unknown

CVE-2020-35605

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
Attacker Value
Unknown

CVE-2020-8149

Disclosure Date: May 15, 2020 (last updated February 21, 2025)
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.