Code Editor Vulnerability in Kakoune from Mawww
CVE-2026-48120
8.6HIGH
What is CVE-2026-48120?
Kakoune, a popular code editor, has a vulnerability that allows attackers to execute arbitrary commands through malicious backup files. This issue arises from the default scripting behavior of the 'autorestore.kak' script, which is activated before version 2026.05.21. When users open files that utilize these compromised backup files, both Kakoune and shell commands are executed without user consent. To mitigate this issue, users can disable the auto-restore feature by adding 'autorestore-disable' to their user kakrc settings, or they can upgrade to version 2026.05.21, which resolves the vulnerability.
Affected Version(s)
kakoune < 2026.05.21
