CVE-2026-48120

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-07 23:17

Updated : 2026-09-09 20:55


NVD link : CVE-2026-48120

Mitre link : CVE-2026-48120

CVE.ORG link : CVE-2026-48120


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')