What is CVE-2026-48120?
CVE-2026-48120 is a vulnerability in the Kakoune code editor. Prior to version 2026.05.21, the bundled and default-enabled `autorestore.kak` script could be exploited via malicious backup files, leading to arbitrary Kakoune and shell command execution. Upgrading to Kakoune 2026.05.21 addresses this issue.
Azərbaycanca: CVE-2026-48120, Kakoune kod redaktorunda aşkarlanmış boşluqdur. 2026.05.21 versiyasından əvvəl, standart olaraq aktiv olan `autorestore.kak` skripti zərərli backup faylları vasitəsilə ixtiyari Kakoune və shell əmrlərinin icrasına səbəb ola bilər. Problemi aradan qaldırmaq üçün Kakoune-u 2026.05.21 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which component of Kakoune does CVE-2026-48120 affect?
CVE-2026-48120 affects the default-enabled `autorestore.kak` script in the Kakoune code editor.
What action is recommended to mitigate CVE-2026-48120?
Upgrading Kakoune to version 2026.05.21 is recommended to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.