A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacsUpgrade emacs-lucidUpgrade emacs-common | Mar 19, 2025 | Feb 12, 2025 |
| Amazon Linux Ami 2 | — | Upgrade emacs-lucidUpgrade emacs-commonUpgrade emacs-noxUpgrade emacs-develUpgrade emacs-filesystemUpgrade emacs-terminalUpgrade emacs-debuginfoUpgrade emacs | Mar 10, 2025 | Feb 12, 2025 |
| Amazon_linux | — | Upgrade emacs | Mar 18, 2025 | Feb 12, 2025 |
| Amazon_linux_2023 | — | Upgrade emacs-debugsourceUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-filesystemUpgrade emacs-nox-debuginfoUpgrade emacs-develUpgrade emacs-noxUpgrade emacs-common-debuginfoUpgrade emacs-lucidUpgrade emacs-debuginfoUpgrade emacs | Mar 10, 2025 | Feb 12, 2025 |
| Debian | — | Upgrade emacs | Feb 28, 2025 | Feb 12, 2025 |
| Freebsd | — | Upgrade emacs-noxUpgrade emacsUpgrade emacs-cannaUpgrade emacs-devel-noxUpgrade emacs-develUpgrade emacs-wayland | Feb 25, 2025 | Feb 24, 2025 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Jun 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 13, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Apr 11, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade emacs-filesystem | May 7, 2025 | Feb 12, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade emacs-filesystem | Jun 11, 2025 | Feb 12, 2025 |
| Oracle_linux | — | Upgrade emacs-commonUpgrade emacsUpgrade emacs-elUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacs-noxUpgrade emacs-lucid | Mar 3, 2025 | Feb 12, 2025 |
| Redhat_linux | — | Upgrade emacs-lucidNo solution existsUpgrade emacs-debugsourceUpgrade emacs-elUpgrade emacs-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacs-lucid-debuginfoUpgrade emacs-commonUpgrade emacs-filesystemUpgrade emacs-terminalUpgrade emacsUpgrade emacs-common-debuginfoUpgrade emacs-nox | Feb 28, 2025 | Feb 12, 2025 |
| Rocky_linux | — | Upgrade emacs-lucidUpgrade emacs-noxUpgrade emacsUpgrade emacs-common-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacs-debugsourceUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-debuginfo | May 8, 2025 | Feb 12, 2025 |
| Suse | — | Upgrade emacsUpgrade emacs-infoUpgrade etagsUpgrade emacs-elnUpgrade emacs-x11Upgrade emacs-noxUpgrade emacs-el | Feb 20, 2025 | Feb 12, 2025 |
| Ubuntu | — | Upgrade emacs-pgtk (Ubuntu Pro)Upgrade emacs (Ubuntu Pro)Upgrade emacs-nox (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacs-common (Ubuntu Pro)Upgrade emacs-bin-common (Ubuntu Pro)Upgrade emacs-lucid (Ubuntu Pro)Upgrade emacs-gtk (Ubuntu Pro) | Feb 5, 2026 | Feb 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Feb 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub