7.8
CVE-2024-53920
- EPSS 0.53%
- Veröffentlicht 27.11.2024 15:15:26
- Zuletzt bearbeitet 21.09.2026 22:16:54
- Erkennungen
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.403 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.html
https://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92
https://news.ycombinator.com/item?id=42256409
https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html
https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1
https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4
https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg@mail.gmail.com/
http://www.openwall.com/lists/oss-security/2026/08/20/3
http://www.openwall.com/lists/oss-security/2026/08/20/7
http://www.openwall.com/lists/oss-security/2026/09/14/1
http://www.openwall.com/lists/oss-security/2026/09/21/9