

That does not allow remote code execution. An attacker still needs a vector like an SSH session to be able to control kitty. And at that point, if they already have a shell session, they don’t need kitty to do damage.
edit: giving access to other programs is not remote execution, but obviously not a good default.
















yes, I get that and it’s a bad default, but not RCE like the post says