CVE-2026-48120: Mawww Kakoune
High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.
Affected products
- Mawww Kakoune: before 2026.05.21 (fixed in 2026.05.21)
Published 2026-08-07. Last modified 2026-09-09.