Back

CRITICAL

emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code

Published Jun 23, 2024

Description

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

Affected products

Remediation

Red Hat statement

To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file or previewing a crafted email attachment. For this reason, this flaw has been rated with a Moderate security impact.

Red Hat mitigation

Do not open Org mode files or preview email attachments from untrusted sources.

Metrics

References (13)

Change history (3)
  1. CISA ADP
    • SSVC exploitation changed from none to poc
  2. CISA ADP
    • SSVC exploitation changed from poc to none
  3. CISA ADP
    • SSVC exploitation changed from none to poc
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 23, 2024
Updated Aug 22, 2024
Reserved Jun 23, 2024
CISA Vulnrichment
Updated Jul 1, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 23, 2024