CVE-2023-27985
published 2023-03-09CVE-2023-27985: emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.09%
61.6th percentile
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-13 (bookworm) | emacs 1:28.2+1-13 (bookworm) |
| gnu | emacs | >= 0 < 1:28.2+1-13 | 1:28.2+1-13 |
| gnu | emacs | >= 0 < 1:28.2+1-13 | 1:28.2+1-13 |
| gnu | emacs | >= 0 < 1:28.2+1-13 | 1:28.2+1-13 |
| gnu | emacs | 28.1 – 28.2 | — |
| msrc | cbl2_emacs_28.2-4_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification.
vendor_msrc·2023-03-14·CVSS 7.8
CVE-2023-27985 [HIGH] CWE-78 emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification.
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identif
Red Hat
emacs: Shell command injection via a crafted mailto URI
vendor_redhat·2023-03-08·CVSS 7.8
CVE-2023-27985 [HIGH] CWE-77 emacs: Shell command injection via a crafted mailto URI
emacs: Shell command injection via a crafted mailto URI
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
A flaw was found in the Emacs text editor. When opened with emacsclient-mail.desktop, a crafted mailto URI can result in shell command injection due to lack of compliance with the Desktop Entry Specification.
Statement: The emacsclient-mail.desktop file is not distributed in Red Hat Enterprise Linux 6, 7, 8 and 9. Therefore, Red Hat Enterprise Linux is not affected by this flaw.
Package: emacs (Red Hat Enterprise Linux 6) - Not affected
Package: emacs (Red Hat Enterprise Linux 7) - Not affected
Package: emacs
Debian
CVE-2023-27985: emacs - emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell comma...
vendor_debian·2023·CVSS 7.8
CVE-2023-27985 [HIGH] CVE-2023-27985: emacs - emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell comma...
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
Scope: local
bookworm: resolved (fixed in 1:28.2+1-13)
bullseye: resolved
forky: resolved (fixed in 1:28.2+1-13)
sid: resolved (fixed in 1:28.2+1-13)
trixie: resolved (fixed in 1:28.2+1-13)
GHSA
GHSA-f5fq-43fc-vgcr: emacsclient-mail
ghsa_unreviewed·2023-03-09
CVE-2023-27985 [CRITICAL] CWE-78 GHSA-f5fq-43fc-vgcr: emacsclient-mail
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification.
OSV
CVE-2023-27985: emacsclient-mail
osv·2023-03-09·CVSS 7.8
CVE-2023-27985 [HIGH] CVE-2023-27985: emacsclient-mail
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=d32091199ae5de590a83f1542a01d75fba000467http://www.openwall.com/lists/oss-security/2023/03/09/1https://debbugs.gnu.org/cgi/bugreport.cgi?bug=60204https://www.gabriel.urdhr.fr/2023/06/08/emacsclient-mail-shell-elisp-injections/https://www.openwall.com/lists/oss-security/2023/03/08/2http://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=d32091199ae5de590a83f1542a01d75fba000467http://www.openwall.com/lists/oss-security/2023/03/09/1https://debbugs.gnu.org/cgi/bugreport.cgi?bug=60204https://www.gabriel.urdhr.fr/2023/06/08/emacsclient-mail-shell-elisp-injections/https://www.openwall.com/lists/oss-security/2023/03/08/2
2023-03-09
Published