Missing authorization in the kitty drag and drop protocol allows a client to obtain dragged file contents without a drop (CVE-2026-80432) | HOL Guard CVE