Code Editor Vulnerability in Kakoune from Mawww
CVE-2026-48120

8.6HIGH

Key Information:

Vendor

Mawww

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-48120?

Kakoune, a popular code editor, has a vulnerability that allows attackers to execute arbitrary commands through malicious backup files. This issue arises from the default scripting behavior of the 'autorestore.kak' script, which is activated before version 2026.05.21. When users open files that utilize these compromised backup files, both Kakoune and shell commands are executed without user consent. To mitigate this issue, users can disable the auto-restore feature by adding 'autorestore-disable' to their user kakrc settings, or they can upgrade to version 2026.05.21, which resolves the vulnerability.

Affected Version(s)

kakoune < 2026.05.21

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.