Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79992

Опубликовано: 21 авг. 2026
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

Отчет

This is an Important local shell command injection flaw in Emacs TRAMP. An attacker with local access could exploit this vulnerability by tricking a user into processing a maliciously crafted filename, leading to arbitrary command execution. This issue requires user interaction with a malicious file, limiting its remote exploitability.

Меры по смягчению последствий

Users of Emacs TRAMP should avoid processing untrusted filenames or interacting with remote systems that may contain maliciously crafted file names. This operational control reduces the risk of local shell command injection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10emacsAffected
Red Hat Enterprise Linux 6emacsAffected
Red Hat Enterprise Linux 7emacsAffected
Red Hat Enterprise Linux 8emacsAffected
Red Hat Enterprise Linux 9emacsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2523665emacs: local shell command injection through the user field in emacs tramp

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
nvd
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

msrc
7 дней назад

Emacs: local shell command injection through the user field in emacs tramp

CVSS3: 7.8
debian
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this v ...

CVSS3: 7.8
github
11 дней назад

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

7.8 High

CVSS3