Code Execution Flaw in Emacs Affecting Versions Prior to 31.2
CVE-2026-96442

7.8HIGH

What is CVE-2026-96442?

A code execution flaw exists in Emacs that impacts versions prior to 31.2, enabling the Flymake mode to execute arbitrary code from untrusted files during syntax checking. Users editing or viewing files that are not trusted can inadvertently execute code with the privileges of the user running Emacs, creating a significant security risk. It is crucial for users to upgrade to the latest version to mitigate this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.