emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code
Published Jun 23, 2024
9.8
CRITICALCVSS 3.1
EPSS 1.32%
Description
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Affected products
No data.
-
- Version 0StatusaffectedConstraints<29.4
- Version
Red Hat Enterprise Linux 8
emacs-1:26.1-12.el8_10
Fixed · RHSA-2024:6987
Red Hat Enterprise Linux 8
emacs-1:26.1-12.el8_10
Fixed · RHSA-2024:6987
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
emacs-1:26.1-7.el8_6.5
Fixed · RHSA-2024:4971
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
emacs-1:26.1-7.el8_6.5
Fixed · RHSA-2024:4971
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
emacs-1:26.1-7.el8_6.5
Fixed · RHSA-2024:4971
Red Hat Enterprise Linux 8.8 Extended Update Support
emacs-1:26.1-10.el8_8.6
Fixed · RHSA-2024:6203
Red Hat Enterprise Linux 9
emacs-1:27.2-10.el9_4
Fixed · RHSA-2024:6510
Red Hat Enterprise Linux 10
emacs
Affected
Red Hat Enterprise Linux 6
emacs
Out of support scope
Red Hat Enterprise Linux 7
emacs
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | emacs-1:26.1-12.el8_10 | Fixed | RHSA-2024:6987 |
| Red Hat Enterprise Linux 8 | emacs-1:26.1-12.el8_10 | Fixed | RHSA-2024:6987 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | emacs-1:26.1-7.el8_6.5 | Fixed | RHSA-2024:4971 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | emacs-1:26.1-7.el8_6.5 | Fixed | RHSA-2024:4971 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | emacs-1:26.1-7.el8_6.5 | Fixed | RHSA-2024:4971 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | emacs-1:26.1-10.el8_8.6 | Fixed | RHSA-2024:6203 |
| Red Hat Enterprise Linux 9 | emacs-1:27.2-10.el9_4 | Fixed | RHSA-2024:6510 |
| Red Hat Enterprise Linux 10 | emacs | Affected | n/a |
| Red Hat Enterprise Linux 6 | emacs | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | emacs | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file or previewing a crafted email attachment. For this reason, this flaw has been rated with a Moderate security impact.
Red Hat mitigation
Do not open Org mode files or preview email attachments from untrusted sources.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jul 1, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.32% (0.01323) | 69.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.32% (0.01323) | 67.09th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.44% (0.00441) | 62.44th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.70% (0.01703) | 80.80th | v4 (v2025.03.14) |
| Aug 16, 2025 | 0.21% (0.00205) | 42.94th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.23% (0.01235) | 77.83th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 15.00th | v3 (v2023.03.01) |
| Jun 29, 2024 | 0.04% (0.00044) | 13.18th | v3 (v2023.03.01) |
| Jun 24, 2024 | 0.04% (0.00044) | 10.38th | v3 (v2023.03.01) |
References (13)
- https://access.redhat.com/security/cve/CVE-2024-39331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2293942 Issue Tracking
- https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29 Release Notes
- https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8 Mailing ListPatch
- https://list.orgmode.org/87sex5gdqc.fsf%40localhost/ Mailing List
- https://lists.debian.org/debian-lts-announce/2024/06/msg00023.html mailing-listMailing List
- https://lists.debian.org/debian-lts-announce/2024/06/msg00024.html mailing-listMailing List
- https://lists.gnu.org/archive/html/info-gnu-emacs/2024-06/msg00000.html Mailing List
- https://news.ycombinator.com/item?id=40768225 Mailing List
- https://nvd.nist.gov/vuln/detail/CVE-2024-39331
- https://www.cve.org/CVERecord?id=CVE-2024-39331
- https://www.openwall.com/lists/oss-security/2024/06/23/1 Mailing List
- https://www.openwall.com/lists/oss-security/2024/06/23/2 Mailing List
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-39331 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2293942 | Issue Tracking | |
| https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29 | Release Notes | |
| https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8 | Mailing ListPatch | |
| https://list.orgmode.org/87sex5gdqc.fsf%40localhost/ | Mailing List | |
| https://lists.debian.org/debian-lts-announce/2024/06/msg00023.html | mailing-listMailing List | |
| https://lists.debian.org/debian-lts-announce/2024/06/msg00024.html | mailing-listMailing List | |
| https://lists.gnu.org/archive/html/info-gnu-emacs/2024-06/msg00000.html | Mailing List | |
| https://news.ycombinator.com/item?id=40768225 | Mailing List | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-39331 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-39331 | ||
| https://www.openwall.com/lists/oss-security/2024/06/23/1 | Mailing List | |
| https://www.openwall.com/lists/oss-security/2024/06/23/2 | Mailing List |
Change history (3)
- CISA ADP
- SSVC exploitation changed from none to
poc none → poc
- SSVC exploitation changed from none to
poc
- CISA ADP
- SSVC exploitation changed from poc to
none poc → none
- SSVC exploitation changed from poc to
none
- CISA ADP
- SSVC exploitation changed from none to
poc none → poc
- SSVC exploitation changed from none to
poc