Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48120

Опубликовано: 07 авг. 2026
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, autorestore.kak script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add autorestore-disable to the user kakrc will disable the autorestore feature.

EPSS

Процентиль: 4%
0.00137
Низкий

8.6 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.6
debian
3 дня назад

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, en ...

EPSS

Процентиль: 4%
0.00137
Низкий

8.6 High

CVSS3

Дефекты

CWE-74