Source: kakoune
Version: 2024.05.18-2
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for kakoune.

I think this would be no-dsa in principle as needing to edit an
untrusted file to be auto restored. But raising it to RC level as this
shoul be fixed for forky and across down to trixie so far we have only
the 2024.05.18-2 based version.

CVE-2026-48120[0]:
| Kakoune is a code editor. Prior to version 2026.05.21, the bundled,
| enabled by default, `autorestore.kak` script can be exploited by
| malicious backup files leading to arbitrary kakoune and shell
| commands being executed by simply opening a file. Kakoune 2026.05.21
| fixes the issue. As a workaround, add `autorestore-disable` to the
| user kakrc will disable the autorestore feature.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48120
    https://www.cve.org/CVERecord?id=CVE-2026-48120
[1] https://github.com/mawww/kakoune/security/advisories/GHSA-h99r-h8cp-vwcq
[2] 
https://github.com/mawww/kakoune/commit/25c7b13b244fd1ddacc63ecfe1784b5ebc2ba825

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to