oss-sec mailing list archives

Re: Emacs zero-click local command execution via TRAMP


From: Sean Whitton <spwhitton () spwhitton name>
Date: Wed, 26 Aug 2026 10:29:07 +0100

Sean Whitton [21/Aug  2:33pm +01] wrote:
Bas Alberts of the GitHub Security Lab discovered a local command
execution vulnerability in GNU Emacs 30.2 onwards, and possibly earlier.

This has been assigned CVE-2026-79992, with thanks to Marco Benatto.

-- 
Sean Whitton


Current thread: