OS Command Injection Vulnerability in GNU Emacs and TRAMP
CVE-2026-108976

7.8HIGH

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108976?

GNU Emacs versions prior to 31.2 and TRAMP versions before 2.8.2 are susceptible to an OS command injection vulnerability due to an incomplete list of disallowed inputs in the tramp-user-regexp configuration. This flaw allows attackers to potentially execute arbitrary commands by crafting a malicious filename. It is notable that this issue arose because of an inadequate fix for a prior vulnerability, emphasizing the importance of comprehensive security measures in software development.

Affected Version(s)

Emacs 0 < 31.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.