{"id":"DEBIAN-CVE-2026-48120","details":"Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.","modified":"2026-09-10T08:47:29.706447576Z","published":"2026-08-07T23:17:04.117Z","upstream":["CVE-2026-48120"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-48120"}],"affected":[{"package":{"name":"kakoune","ecosystem":"Debian:12","purl":"pkg:deb/debian/kakoune?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2022.10.31-1","2022.10.31-2","2024.05.18-1","2024.05.18-2","2026.05.21-1","2026.05.21-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48120.json"}},{"package":{"name":"kakoune","ecosystem":"Debian:13","purl":"pkg:deb/debian/kakoune?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.05.18-2","2026.05.21-1","2026.05.21-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48120.json"}},{"package":{"name":"kakoune","ecosystem":"Debian:14","purl":"pkg:deb/debian/kakoune?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.05.21-1"}]}],"versions":["2024.05.18-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48120.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}