CVE-2026-48120

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
07/08/2026
Last modified:
07/08/2026

Description

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.