Arbitrary Code Execution in GNU Emacs by GNU Project
CVE-2026-96269
7.5HIGH
What is CVE-2026-96269?
GNU Emacs versions 28.1 through 31.1 are susceptible to a vulnerability that allows arbitrary code execution when a user opens a specially crafted file. This issue arises due to the handling of untrusted values in the read-symbol-shorthands, which can impact the intern and unintern functions. The flaw exists in the default configuration and does not depend on specific user settings to be exploited, making all users of the software at risk.
Affected Version(s)
Emacs 28.1 <= 31.1