n/a vulnerability

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

Published 27 Nov 2024Updated 14 Sep 202610 sources
CVSS 7.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.