Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kakoune has a Critical RCE via Autorestore Backup Filename Injection
Vulnerability Description
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, add `autorestore-disable` to the user kakrc will disable the autorestore feature.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
Maxime Coste Kakoune 输入验证错误漏洞
Vulnerability Description
Maxime Coste Kakoune是Maxime Coste个人开发者的一款模态文本编辑器。 Maxime Coste Kakoune 2026.05.21之前版本存在输入验证错误漏洞,该漏洞源于捆绑的默认启用的autorestore.kak脚本可被恶意备份文件利用,打开文件时可执行任意kakoune和shell命令。
CVSS Information
N/A
Vulnerability Type
N/A