Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: kakoune

Found 1 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-48120
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    13 packages
    • kakoune-cr
    • kakoune-lsp
    • kakoune-unwrapped
    • kakounePlugins.kakoune-lsp
    • kakounePlugins.kakoune-buffers
    • kakounePlugins.kakoune-rainbow
    • kakounePlugins.kakoune-registers
    • kakounePlugins.kakoune-catppuccin
    • kakounePlugins.kakoune-easymotion
    • kakounePlugins.kakoune-state-save
    • kakounePlugins.kakoune-buffer-switcher
    • kakounePlugins.kakoune-extra-filetypes
    • kakounePlugins.kakoune-vertical-selection
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Kakoune has a Critical RCE via Autorestore Backup Filename Injection

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.

Affected products

kakoune
  • ==< 2026.05.21

Matching in nixpkgs

Ignored packages (13)

Package maintainers

Backport needed