{"id":"UBUNTU-CVE-2026-48120","details":"Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.","modified":"2026-08-13T00:08:17Z","published":"2026-08-07T23:17:00Z","upstream":["CVE-2026-48120"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-48120"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-48120"},{"type":"REPORT","url":"https://github.com/mawww/kakoune/commit/25c7b13b244fd1ddacc63ecfe1784b5ebc2ba825"},{"type":"REPORT","url":"https://github.com/mawww/kakoune/security/advisories/GHSA-h99r-h8cp-vwcq"}],"affected":[{"package":{"name":"kakoune","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/kakoune?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0~2016.12.20.1.3a6167ae-1","0~2016.12.20.1.3a6167ae-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"kakoune","binary_version":"0~2016.12.20.1.3a6167ae-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-48120.json"}},{"package":{"name":"kakoune","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/kakoune?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2019.01.20-2","2019.07.01-1","2019.07.01-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2019.07.01-1build1","binary_name":"kakoune"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-48120.json"}},{"package":{"name":"kakoune","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/kakoune?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2020.01.16-3","2020.09.01-3"],"ecosystem_specific":{"binaries":[{"binary_name":"kakoune","binary_version":"2020.09.01-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-48120.json"}},{"package":{"name":"kakoune","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/kakoune?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2022.10.31-2"],"ecosystem_specific":{"binaries":[{"binary_version":"2022.10.31-2","binary_name":"kakoune"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-48120.json"}},{"package":{"name":"kakoune","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/kakoune?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.05.18-2ubuntu1","2024.05.18-2ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"kakoune","binary_version":"2024.05.18-2ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-48120.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}