Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mawww
Mawww kakoune |
|
| Vendors & Products |
Mawww
Mawww kakoune |
Fri, 07 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature. | |
| Title | Kakoune has a Critical RCE via Autorestore Backup Filename Injection | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-08-07T22:34:02.607Z
Updated: 2026-08-11T01:20:08.508Z
Reserved: 2026-05-20T18:46:58.290Z
Link: CVE-2026-48120
Updated: 2026-08-11T01:20:02.589Z
Status : Received
Published: 2026-08-07T23:17:04.117
Modified: 2026-08-11T02:16:51.257
Link: CVE-2026-48120