CVE-2026-48120

Source
https://cve.org/CVERecord?id=CVE-2026-48120
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48120.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48120
Aliases
  • GHSA-h99r-h8cp-vwcq
Downstream
Published
2026-08-07T22:34:02.607Z
Modified
2026-08-08T15:04:22.812560Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Kakoune has a Critical RCE via Autorestore Backup Filename Injection
Details

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, autorestore.kak script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add autorestore-disable to the user kakrc will disable the autorestore feature.

Database specific
{
    "cwe_ids": [
        "CWE-74"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48120.json"
}
References

Affected packages

Git / github.com/mawww/kakoune

Affected ranges

Type
GIT
Repo
https://github.com/mawww/kakoune
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2026.05.21"
        }
    ]
}

Affected versions

v2018.*
v2018.04.13
v2018.09.04
v2018.10.27
Other
v20180409
v2019.*
v2019.01.20
v2019.07.01
v2019.12.10
v2020.*
v2020.01.16
v2020.08.04
v2020.09.01
v2021.*
v2021.08.28
v2021.10.28
v2021.11.08
v2022.*
v2022.10.31
v2023.*
v2023.07.29
v2023.08.05
v2024.*
v2024.05.09
v2024.05.18
v2025.*
v2025.06.03
v2026.*
v2026.04.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48120.json"
vanir_signatures_modified
"2026-08-08T15:04:22Z"
vanir_signatures
[
    {
        "digest": {
            "line_hashes": [
                "128495886531965262996541097277457311222",
                "80875189594521831869114628986674075728",
                "329997126514369219202846194224370385862",
                "97158121025604836355451783740262182794",
                "40047562719486121863037407613896888184",
                "323453739393177447376236665399840768355",
                "303778251511019835848770699201801619722",
                "286508314168956282742731727002431979980",
                "291742790962387901507933038406493762379",
                "107448851313047533440757017120110586705"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2026-48120-f38539cb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/mawww/kakoune/commit/36ad52ebf983c1b23182caccd4f792517235b06d",
        "target": {
            "file": "src/main.cc"
        }
    }
]