Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature. | |
| Title | Kakoune has a Critical RCE via Autorestore Backup Filename Injection | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-07T22:34:02.607Z
Reserved: 2026-05-20T18:46:58.290Z
Link: CVE-2026-48120
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T23:30:17Z
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')