Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, autorestore.kak script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add autorestore-disable to the user kakrc will disable the autorestore feature.
{
"cwe_ids": [
"CWE-74"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48120.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48120.json"
"2026-08-08T15:04:22Z"
[
{
"digest": {
"line_hashes": [
"128495886531965262996541097277457311222",
"80875189594521831869114628986674075728",
"329997126514369219202846194224370385862",
"97158121025604836355451783740262182794",
"40047562719486121863037407613896888184",
"323453739393177447376236665399840768355",
"303778251511019835848770699201801619722",
"286508314168956282742731727002431979980",
"291742790962387901507933038406493762379",
"107448851313047533440757017120110586705"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-48120-f38539cb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/mawww/kakoune/commit/36ad52ebf983c1b23182caccd4f792517235b06d",
"target": {
"file": "src/main.cc"
}
}
]