A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-lucidUpgrade emacsUpgrade emacs-commonUpgrade emacs-filesystem | Mar 19, 2025 | Feb 12, 2025 |
| Amazon Linux Ami 2 | — | Upgrade emacs-develUpgrade emacs-commonUpgrade emacs-noxUpgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacsUpgrade emacs-terminalUpgrade emacs-debuginfo | Mar 10, 2025 | Feb 12, 2025 |
| Amazon_linux | — | Upgrade emacs | Mar 18, 2025 | Feb 12, 2025 |
| Amazon_linux_2023 | — | Upgrade emacs-lucid-debuginfoUpgrade emacs-debugsourceUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacs-nox-debuginfoUpgrade emacs-commonUpgrade emacs-develUpgrade emacsUpgrade emacs-noxUpgrade emacs-lucidUpgrade emacs-debuginfoUpgrade emacs-common-debuginfo | Mar 10, 2025 | Feb 12, 2025 |
| Debian | — | Upgrade emacs | Feb 28, 2025 | Feb 12, 2025 |
| Freebsd | — | Upgrade emacsUpgrade emacs-cannaUpgrade emacs-noxUpgrade emacs-develUpgrade emacs-devel-noxUpgrade emacs-wayland | Feb 25, 2025 | Feb 24, 2025 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Jun 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Apr 11, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade emacs-filesystem | May 7, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade emacs-filesystem | Jun 11, 2025 | Feb 12, 2025 |
| Oracle_linux | — | Upgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacsUpgrade emacs-elUpgrade emacs-common | Mar 3, 2025 | Feb 12, 2025 |
| Redhat_linux | — | Upgrade emacsUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacs-noxUpgrade emacs-common-debuginfoUpgrade emacs-debugsourceNo solution existsUpgrade emacs-elUpgrade emacs-lucid-debuginfoUpgrade emacs-debuginfoUpgrade emacs-lucidUpgrade emacs-nox-debuginfoUpgrade emacs-common | Feb 28, 2025 | Feb 12, 2025 |
| Rocky_linux | — | Upgrade emacs-debuginfoUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-debugsourceUpgrade emacs-nox-debuginfoUpgrade emacsUpgrade emacs-common-debuginfoUpgrade emacs-noxUpgrade emacs-lucid | May 8, 2025 | Feb 12, 2025 |
| Suse | — | Upgrade etagsUpgrade emacs-elUpgrade emacs-elnUpgrade emacs-noxUpgrade emacs-x11Upgrade emacsUpgrade emacs-info | Feb 20, 2025 | Feb 12, 2025 |
| Ubuntu | — | Upgrade emacs-common (Ubuntu Pro)Upgrade emacs (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacs-pgtk (Ubuntu Pro)Upgrade emacs-nox (Ubuntu Pro)Upgrade emacs-bin-common (Ubuntu Pro)Upgrade emacs-lucid (Ubuntu Pro)Upgrade emacs-gtk (Ubuntu Pro) | Feb 5, 2026 | Feb 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Feb 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub