{"id":"UBUNTU-CVE-2025-43929","details":"open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).","modified":"2026-06-17T16:15:06.644717776Z","published":"2025-04-20T03:15:00Z","upstream":["CVE-2025-43929"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-43929"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-43929"},{"type":"REPORT","url":"https://ghostwriter.kde.org/documentation/#links"},{"type":"REPORT","url":"https://github.com/0xBenCantCode/CVE-2025-43929"},{"type":"REPORT","url":"https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0"},{"type":"REPORT","url":"https://hitman.services/cve-2025-43929/"}],"affected":[{"package":{"name":"kitty","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.26.5-3ubuntu2","0.26.5-5ubuntu1","0.31.0-3","0.31.0-4","0.32.2-1","0.32.2-1build2","0.32.2-1build3","0.32.2-1ubuntu0.1","0.32.2-1ubuntu0.2","0.32.2-1ubuntu0.3","0.32.2-1ubuntu0.4"],"ecosystem_specific":{"binaries":[{"binary_version":"0.32.2-1ubuntu0.4","binary_name":"kitty"},{"binary_version":"0.32.2-1ubuntu0.4","binary_name":"kitty-shell-integration"},{"binary_version":"0.32.2-1ubuntu0.4","binary_name":"kitty-terminfo"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-43929.json"}},{"package":{"name":"kitty","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.39.1-1","0.41.1-2","0.41.1-2+deb13u1build0.25.10.1"],"ecosystem_specific":{"binaries":[{"binary_name":"kitty","binary_version":"0.41.1-2+deb13u1build0.25.10.1"},{"binary_version":"0.41.1-2+deb13u1build0.25.10.1","binary_name":"kitty-shell-integration"},{"binary_name":"kitty-terminfo","binary_version":"0.41.1-2+deb13u1build0.25.10.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-43929.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}