OS Command Injection Affecting gvisor-tap-vsock-gvforwarder package, versions *


Severity

Recommended
0.0
high
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-GVISORTAPVSOCKGVFORWARDER-18742056
  • published13 Aug 2026
  • disclosed10 Aug 2026

Introduced: 10 Aug 2026

NewCVE-2026-72913  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

There is no fixed version for Centos:10 gvisor-tap-vsock-gvforwarder.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gvisor-tap-vsock-gvforwarder package and not the gvisor-tap-vsock-gvforwarder package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command characters and handle_remote_ssh calls get_ssh_data in kittens/ssh/utils.py, which emits a newline; chaining the handlers can execute attacker-controlled commands when a user displays untrusted terminal data. This issue is fixed in version 0.48.2.

CVSS Base Scores

version 3.1