CVE-2026-48120 HIGH

CVE-2026-48120: Kakoune has a Critical RCE via Autorestore Backup Filename Injection

Vendor Mawww
Product kakoune
Weakness CWE-74
Published August 7, 2026
Last update August 11, 2026

CVSS base score

8.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.

Key dates

02Disclosure timeline

August 7, 2026 CVE published
August 11, 2026 Record updated

Related vulnerabilities

04Related CVE