{"api_version":"v1","generated_at":"2026-10-08T06:35:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-kovidgoyal-kitty-929b28f1fe3a","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/kitty","name":"kitty","next_cursor":null,"observations":[{"affected":"< 0.48.2","affected_versions_present":true,"cve_id":"CVE-2026-72913","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-72913","fixed":"0.48.2.","last_modified":"2026-08-11T15:59:44.886Z","patch_url":"https://github.com/kovidgoyal/kitty/security/advisories/GHSA-ccp2-q4v6-rw94","primary_source":"","published":"2026-08-10T21:07:29.557Z"},{"affected":"< 0.47.3","affected_versions_present":true,"cve_id":"CVE-2026-54057","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54057","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-16T03:55:59.652Z","patch_url":"","primary_source":"","published":"2026-06-12T20:07:00.209Z"},{"affected":">= 0.47.0, < 0.47.2","affected_versions_present":true,"cve_id":"CVE-2026-54056","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54056","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T13:03:10.902Z","patch_url":"https://github.com/kovidgoyal/kitty/security/advisories/GHSA-r892-cv7q-fw8x","primary_source":"","published":"2026-06-12T20:06:06.437Z"},{"affected":"< 0.47.2","affected_versions_present":true,"cve_id":"CVE-2026-54055","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54055","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T19:28:17.461Z","patch_url":"https://github.com/kovidgoyal/kitty/security/advisories/GHSA-q446-x7q6-vcxh","primary_source":"","published":"2026-06-12T20:03:17.907Z"},{"affected":"< 0.47.0","affected_versions_present":true,"cve_id":"CVE-2026-42851","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42851","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-16T13:12:55.145Z","patch_url":"https://github.com/kovidgoyal/kitty/security/advisories/GHSA-w98g-hpvr-r332","primary_source":"","published":"2026-06-12T20:00:23.386Z"},{"affected":"< 0.47.0","affected_versions_present":true,"cve_id":"CVE-2026-42850","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42850","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-16T03:56:03.100Z","patch_url":"","primary_source":"","published":"2026-06-12T19:59:14.267Z"},{"affected":"< 0.47.0","affected_versions_present":true,"cve_id":"CVE-2026-33642","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33642","fixed":"0.47.0.","last_modified":"2026-05-19T19:13:23.671Z","patch_url":"https://github.com/kovidgoyal/kitty/commit/e9661f0f3afb4e4dbffa509adfb3df3c9780ad34","primary_source":"","published":"2026-05-19T18:04:42.482Z"},{"affected":"< 0.47.0","affected_versions_present":true,"cve_id":"CVE-2026-33633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33633","fixed":"0.47.0.","last_modified":"2026-05-20T03:55:46.409Z","patch_url":"https://github.com/kovidgoyal/kitty/commit/e9661f0f3afb4e4dbffa509adfb3df3c9780ad34","primary_source":"","published":"2026-05-19T17:36:07.762Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"kovidgoyal"}}
