Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42vv-cfp2-9qc8

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

EPSS

Процентиль: 3%
0.00135
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
redhat
15 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
nvd
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

msrc
7 дней назад

Emacs: local shell command injection through the user field in emacs tramp

CVSS3: 7.8
debian
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this v ...

EPSS

Процентиль: 3%
0.00135
Низкий

7.8 High

CVSS3

Дефекты

CWE-78