Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-43929 — High severity vulnerability in KiTTY allowing for local executables to be ran without user confirmation under certain circumstances. | Kitploit
Tools/GitHubGitHub/0xbencantcode/cve-2025-43929
Vulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary Exploitation
GitHub0xbencantcode/cve-2025-43929

CVE-2025-43929

High severity vulnerability in KiTTY allowing for local executables to be ran without user confirmation under certain circumstances.

View Repository
81 year agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-43929

Proof-of-concept for CVE-2025-43929, a high-severity vulnerability in KiTTY allowing for local executables to be ran without user confirmation under certain circumstances

Vulnerability Type

CWE-346: CWE-346 Origin Validation Error

Vulnerability Description

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

Vulnerability Demo

https://github.com/user-attachments/assets/87f0b35e-97b4-4b11-b495-b0112ae590e5

Download Tool