A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-commonUpgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacs | Mar 19, 2025 | Feb 12, 2025 |
| Amazon Linux Ami 2 | — | Upgrade emacs-lucidUpgrade emacs-develUpgrade emacs-noxUpgrade emacs-commonUpgrade emacs-debuginfoUpgrade emacs-filesystemUpgrade emacsUpgrade emacs-terminal | Mar 10, 2025 | Feb 12, 2025 |
| Amazon_linux | — | Upgrade emacs | Mar 18, 2025 | Feb 12, 2025 |
| Amazon_linux_2023 | — | Upgrade emacs-lucidUpgrade emacs-common-debuginfoUpgrade emacs-debuginfoUpgrade emacsUpgrade emacs-noxUpgrade emacs-develUpgrade emacs-nox-debuginfoUpgrade emacs-filesystemUpgrade emacs-commonUpgrade emacs-terminalUpgrade emacs-debugsourceUpgrade emacs-lucid-debuginfo | Mar 10, 2025 | Feb 12, 2025 |
| Debian | — | Upgrade emacs | Feb 28, 2025 | Feb 12, 2025 |
| Freebsd | — | Upgrade emacs-waylandUpgrade emacs-devel-noxUpgrade emacs-develUpgrade emacsUpgrade emacs-noxUpgrade emacs-canna | Feb 25, 2025 | Feb 24, 2025 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Jun 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Apr 11, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade emacs-filesystem | May 7, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade emacs-filesystem | Jun 11, 2025 | Feb 12, 2025 |
| Oracle_linux | — | Upgrade emacs-filesystemUpgrade emacs-noxUpgrade emacs-lucidUpgrade emacs-terminalUpgrade emacs-elUpgrade emacs-commonUpgrade emacs | Mar 3, 2025 | Feb 12, 2025 |
| Redhat_linux | — | Upgrade emacs-lucid-debuginfoUpgrade emacs-elUpgrade emacs-debuginfoUpgrade emacs-lucidUpgrade emacs-nox-debuginfoUpgrade emacs-commonNo solution existsUpgrade emacs-debugsourceUpgrade emacsUpgrade emacs-noxUpgrade emacs-common-debuginfoUpgrade emacs-terminalUpgrade emacs-filesystem | Feb 28, 2025 | Feb 12, 2025 |
| Rocky_linux | — | Upgrade emacs-commonUpgrade emacs-debuginfoUpgrade emacs-debugsourceUpgrade emacs-lucid-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacsUpgrade emacs-common-debuginfoUpgrade emacs-noxUpgrade emacs-lucid | May 8, 2025 | Feb 12, 2025 |
| Suse | — | Upgrade etagsUpgrade emacs-x11Upgrade emacs-elnUpgrade emacs-noxUpgrade emacs-elUpgrade emacs-infoUpgrade emacs | Feb 20, 2025 | Feb 12, 2025 |
| Ubuntu | — | Upgrade emacs (Ubuntu Pro)Upgrade emacs-common (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacs-nox (Ubuntu Pro)Upgrade emacs-bin-common (Ubuntu Pro)Upgrade emacs-pgtk (Ubuntu Pro)Upgrade emacs-gtk (Ubuntu Pro)Upgrade emacs-lucid (Ubuntu Pro) | Feb 5, 2026 | Feb 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Feb 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub