Command Injection Vulnerability in GNU Emacs by GNU
CVE-2022-48339
7.8HIGH
What is CVE-2022-48339?
A vulnerability has been identified in GNU Emacs that allows for command injection through the 'hfy-istext-command' function. The function improperly handles user-supplied input for file and directory parameters without escaping potentially harmful shell metacharacters. This oversight could lead to the execution of arbitrary code if an attacker manipulates file or directory names. It is crucial for users to update to the latest version to mitigate this risk.