PT-2023-21468 · Emacs+1 · Emacs+1
Gabriel Corona
·
Published
2023-03-09
·
Updated
2025-03-05
·
CVE-2023-27986
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Emacs versions 28.1 through 28.2
Description
The issue allows for Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters.
Recommendations
For versions 28.1 through 28.2, update to version 29.0.90 or later to resolve the issue.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Emacs