CVE-2024-53920

Public on 2024-11-27
Modified on 2024-11-29
Description
In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
Severity
Important severity
Important
CVSS v3 Base Score
7.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 emacs Not Affected
HAQM Linux 2 - Core emacs 2025-02-12 ALAS2-2025-2757 Fixed
HAQM Linux 2023 emacs 2025-02-12 ALAS2023-2025-849 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NVD CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H