CVE-2023-28617
published 2023-03-19CVE-2023-28617: org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.47%
37.6th percentile
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-14 (bookworm) | emacs 1:28.2+1-14 (bookworm) |
| debian | emacs | — | — |
| debian | org-mode | < emacs 1:28.2+1-14 (bookworm) | emacs 1:28.2+1-14 (bookworm) |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | >= 0 < 1:27.1+1-3.1+deb11u6 | 1:27.1+1-3.1+deb11u6 |
| gnu | emacs | >= 0 < 1:28.2+1-14 | 1:28.2+1-14 |
| gnu | emacs | >= 0 < 1:28.2+1-14 | 1:28.2+1-14 |
| gnu | emacs | >= 0 < 1:28.2+1-14 | 1:28.2+1-14 |
| gnu | emacs | >= 0 < 1:27.1+1-3ubuntu5.2 | 1:27.1+1-3ubuntu5.2 |
| gnu | emacs | >= 0 < 1:26.3+1-1ubuntu2+esm1 | 1:26.3+1-1ubuntu2+esm1 |
| gnu | emacs | >= 0 < 1:29.3+1-1ubuntu2+esm1 | 1:29.3+1-1ubuntu2+esm1 |
| gnu | org_mode | <= 9.6.1 | — |
| msrc | cbl2_emacs_28.2-5_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Org Mode vulnerabilities
vendor_ubuntu·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] Org Mode vulnerabilities
Title: Org Mode vulnerabilities
Summary: Several security issues were fixed in Org Mode.
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This iss
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2024-09-19·CVSS 7.8
CVE-2024-39331 [HIGH] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Several security issues were fixed in Emacs.
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discov
Red Hat
emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux
vendor_redhat·2023-05-09·CVSS 7.8
CVE-2023-2491 [HIGH] CWE-77 emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux
emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Statement: This issue only affects Red
Ubuntu
Emacs vulnerability
vendor_ubuntu·2023-04-06
CVE-2023-28617 Emacs vulnerability
Title: Emacs vulnerability
Summary: Emacs could be made to run programs as your login if it received specially crafted input.
Xi Lu discovered that Emacs did not properly handle certain
inputs. An attacker could possibly use this issue to execute
arbitrary commands.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
emacs: command injection vulnerability in org-mode
vendor_redhat·2023-03-19·CVSS 7.8
CVE-2023-28617 [HIGH] CWE-77 emacs: command injection vulnerability in org-mode
emacs: command injection vulnerability in org-mode
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the function org-babel-execute:latex in ob-latex.el can result in arbitrary command execution.
Mitigation: Do not evaluate untrusted Lisp or org-mode code.
Package: emacs (Red Hat Enterprise Linux 6) - Not affected
Package: emacs (Red Hat Enterprise Linux 7) - Not affected
Microsoft
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
vendor_msrc·2023-03-14·CVSS 7.8
CVE-2023-28617 [HIGH] CWE-78 org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE
Debian
CVE-2023-2491: emacs - A flaw was found in the Emacs text editor. Processing a specially crafted org-mo...
vendor_debian·2023·CVSS 7.8
CVE-2023-2491 [HIGH] CVE-2023-2491: emacs - A flaw was found in the Emacs text editor. Processing a specially crafted org-mo...
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2023-28617: emacs - org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs a...
vendor_debian·2023·CVSS 7.8
CVE-2023-28617 [HIGH] CVE-2023-28617: emacs - org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs a...
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-14)
bullseye: resolved (fixed in 1:27.1+1-3.1+deb11u6)
forky: resolved (fixed in 1:28.2+1-14)
sid: resolved (fixed in 1:28.2+1-14)
trixie: resolved (fixed in 1:28.2+1-14)
OSV
org-mode vulnerabilities
osv·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] org-mode vulnerabilities
org-mode vulnerabilities
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
OSV
emacs, emacs24, emacs25 vulnerabilities
osv·2024-09-19·CVSS 7.8
CVE-2022-45939 [HIGH] emacs, emacs24, emacs25 vulnerabilities
emacs, emacs24, emacs25 vulnerabilities
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discovered that Emacs incorrectly handled input sa
GHSA
GHSA-2hj6-9wp7-hvmh: A flaw was found in the Emacs text editor
ghsa_unreviewed·2023-05-18·CVSS 7.8
CVE-2023-2491 [HIGH] CWE-77 GHSA-2hj6-9wp7-hvmh: A flaw was found in the Emacs text editor
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
OSV
CVE-2023-28617: org-babel-execute:latex in ob-latex
osv·2023-03-19·CVSS 7.8
CVE-2023-28617 [HIGH] CVE-2023-28617: org-babel-execute:latex in ob-latex
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
GHSA
GHSA-xwfh-qqww-gr22: org-babel-execute:latex in ob-latex
ghsa_unreviewed·2023-03-19
CVE-2023-28617 [CRITICAL] CWE-78 GHSA-xwfh-qqww-gr22: org-babel-execute:latex in ob-latex
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=8f8ec2ccf3f5ef8f38d68ec84a7e4739c45db485https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=a8006ea580ed74f27f974d60b598143b04ad1741https://list.orgmode.org/tencent_04CF842704737012CCBCD63CD654DD41CA0A%40qq.com/T/#m6ef8e7d34b25fe17b4cbb655b161edce18c6655ehttps://lists.debian.org/debian-lts-announce/2023/05/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00019.htmlhttps://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=8f8ec2ccf3f5ef8f38d68ec84a7e4739c45db485https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=a8006ea580ed74f27f974d60b598143b04ad1741https://list.orgmode.org/tencent_04CF842704737012CCBCD63CD654DD41CA0A%40qq.com/T/#m6ef8e7d34b25fe17b4cbb655b161edce18c6655ehttps://lists.debian.org/debian-lts-announce/2023/05/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2025/02/msg00033.html
2023-03-19
Published