PT-2025-6868 · Emacs+11 · Emacs+11
Maxim Nikulin
·
Published
2025-02-12
·
Updated
2026-02-04
·
CVE-2025-1244
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Emacs (affected versions not specified)
Description:
A command injection flaw was found in the Emacs text editor, allowing a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. This can be achieved by tricking users into visiting a specially crafted website or an HTTP URL with a redirect. The flaw is related to improper handling of custom "man" URI schemes.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Emacs
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu