OS Command Injection Vulnerability in GNU Emacs and TRAMP
CVE-2026-108976
7.8HIGH
What is CVE-2026-108976?
GNU Emacs versions prior to 31.2 and TRAMP versions before 2.8.2 are susceptible to an OS command injection vulnerability due to an incomplete list of disallowed inputs in the tramp-user-regexp configuration. This flaw allows attackers to potentially execute arbitrary commands by crafting a malicious filename. It is notable that this issue arose because of an inadequate fix for a prior vulnerability, emphasizing the importance of comprehensive security measures in software development.
Affected Version(s)
Emacs 0 < 31.2