CVE-2026-95834 | Kovid Goyal Kitty up to 0.48.x Drag Source Path kitty/dnd.c drag_remote_file_data use after free

SecurityVulns

A vulnerability described as problematic has been identified in Kovid Goyal Kitty up to 0.48.x. This vulnerability affects the function drag_remote_file_data of the file kitty/dnd.c of the component Drag Source Path. Executing a manipulation can lead to use after free.

This vulnerability is registered as CVE-2026-95834. The attack needs to be launched locally. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More