PT-2026-69157 · Kakoune · Kakoune

CVE-2026-48120

·

Published

2026-08-07

·

Updated

2026-08-11

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kakoune versions prior to 2026.05.21
Description The bundled autorestore.kak script, which is enabled by default, allows the execution of arbitrary shell and editor commands when a user opens a file if malicious backup files are present.
Recommendations Update to version 2026.05.21. As a temporary workaround, add autorestore-disable to the user kakrc to disable the autorestore feature.

Exploit

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48120
GHSA-H99R-H8CP-VWCQ

Affected Products

Kakoune