Source: kakoune Version: 2024.05.18-2 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for kakoune. I think this would be no-dsa in principle as needing to edit an untrusted file to be auto restored. But raising it to RC level as this shoul be fixed for forky and across down to trixie so far we have only the 2024.05.18-2 based version. CVE-2026-48120[0]: | Kakoune is a code editor. Prior to version 2026.05.21, the bundled, | enabled by default, `autorestore.kak` script can be exploited by | malicious backup files leading to arbitrary kakoune and shell | commands being executed by simply opening a file. Kakoune 2026.05.21 | fixes the issue. As a workaround, add `autorestore-disable` to the | user kakrc will disable the autorestore feature. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-48120 https://www.cve.org/CVERecord?id=CVE-2026-48120 [1] https://github.com/mawww/kakoune/security/advisories/GHSA-h99r-h8cp-vwcq [2] https://github.com/mawww/kakoune/commit/25c7b13b244fd1ddacc63ecfe1784b5ebc2ba825 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

