PT-2023-21850 · Gnu Emacs+10 · Gnu Emacs+10

Lux

+1

·

Published

2023-03-18

·

Updated

2025-08-14

·

CVE-2023-28617

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Org Mode versions through 9.6.1
Description The issue allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters. This is possible due to a flaw in the org-babel-execute:latex function in ob-latex.el for GNU Emacs.
Recommendations For versions through 9.6.1, consider disabling the org-babel-execute:latex function until a patch is available to prevent the execution of arbitrary commands. Restrict access to file names and directory names that may contain shell metacharacters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:1930
ALSA-2023:2074
ALSA-2023:2626
ALSA-2023:3104
AZL-25707
BDU:2025-11741
CESA-2023_1930
CVE-2023-28617
DLA-3416-1
DLA-3616-1
DLA-4069-1
MGASA-2023-0152
OESA-2023-1185
RHSA-2023:1915
RHSA-2023:1930
RHSA-2023:1931
RHSA-2023:1958
RHSA-2023:2010
RHSA-2023:2074
RHSA-2023:3189
RHSA-2023_1930
RHSA-2023_2074
RLSA-2023:1930
RLSA-2023:2074
USN-6003-1
USN-7027-1
USN-7375-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Gnu Emacs
Linuxmint
Org Mode
Red Hat
Red Os
Rocky Linux
Ubuntu