A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade emacs-terminalUpgrade emacs-nox-debuginfoUpgrade emacs-noxUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-lucidUpgrade emacs-develUpgrade emacs-common-debuginfoUpgrade emacs-debugsourceUpgrade emacs-debuginfoUpgrade emacs-filesystemUpgrade emacs | Sep 30, 2026 | Aug 25, 2026 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Aug 26, 2026 | Aug 24, 2026 |
| Redhat_linux | — | No solution exists | Aug 27, 2026 | Aug 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub