CVE-2024-30202
published 2024-03-25CVE-2024-30202: In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.10%
61.8th percentile
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-15+deb12u1 (bookworm) | emacs 1:28.2+1-15+deb12u1 (bookworm) |
| debian | org-mode | < emacs 1:28.2+1-15+deb12u1 (bookworm) | emacs 1:28.2+1-15+deb12u1 (bookworm) |
| gnu | emacs | < 29.3 | 29.3 |
| gnu | emacs | >= 0 < 1:28.2+1-15+deb12u1 | 1:28.2+1-15+deb12u1 |
| gnu | emacs | >= 0 < 1:29.3+1-1 | 1:29.3+1-1 |
| gnu | emacs | >= 0 < 1:29.3+1-1 | 1:29.3+1-1 |
| gnu | org_mode | < 9.6.23 | 9.6.23 |
| msrc | azl3_emacs_29.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_emacs_29.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_emacs_28.2-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_emacs_29.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
org-mode vulnerabilities
osv·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] org-mode vulnerabilities
org-mode vulnerabilities
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
GHSA
GHSA-8r8f-v2fj-h7cp: In Emacs before 29
ghsa_unreviewed·2024-03-25
CVE-2024-30202 [HIGH] CWE-94 GHSA-8r8f-v2fj-h7cp: In Emacs before 29
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
OSV
CVE-2024-30202: In Emacs before 29
osv·2024-03-25·CVSS 7.8
CVE-2024-30202 [HIGH] CVE-2024-30202: In Emacs before 29
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
Ubuntu
Org Mode vulnerabilities
vendor_ubuntu·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] Org Mode vulnerabilities
Title: Org Mode vulnerabilities
Summary: Several security issues were fixed in Org Mode.
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This iss
Red Hat
emacs: arbitrary Lisp code is evaluated as part of turning on Org mode
vendor_redhat·2024-03-25·CVSS 7.8
CVE-2024-30202 [HIGH] CWE-95 emacs: arbitrary Lisp code is evaluated as part of turning on Org mode
emacs: arbitrary Lisp code is evaluated as part of turning on Org mode
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
A flaw was found in Emacs. Arbitrary Lisp code can be evaluated when an Org mode file is opened or when the Org mode is being enabled, resulting in arbitrary code execution.
Statement: The Emacs package, as shipped in Red Hat Enterprise Linux 8 and 9, is not affected by this vulnerability because the vulnerable code was introduced in a newer version of Emacs.
To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file. For this reason, this flaw has been rated with a Moderate security impact.
Mitigation: Do not open Org mode files from untrusted sources.
Packag
Microsoft
In Emacs before 29.3 arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
vendor_msrc·2024-03-12·CVSS 7.8
CVE-2024-30202 [HIGH] CWE-94 In Emacs before 29.3 arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
In Emacs before 29.3 arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Require
Debian
CVE-2024-30202: emacs - In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org...
vendor_debian·2024·CVSS 7.8
CVE-2024-30202 [HIGH] CVE-2024-30202: emacs - In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org...
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-15+deb12u1)
bullseye: resolved
forky: resolved (fixed in 1:29.3+1-1)
sid: resolved (fixed in 1:29.3+1-1)
trixie: resolved (fixed in 1:29.3+1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/03/25/2http://www.openwall.com/lists/oss-security/2024/04/08/6https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=befa9fcaae29a6c9a283ba371c3c5234c7f644ebhttps://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=003ddacf1c8d869b1858181c29ea21b731a8d8d9http://www.openwall.com/lists/oss-security/2024/03/25/2http://www.openwall.com/lists/oss-security/2024/04/08/6https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=befa9fcaae29a6c9a283ba371c3c5234c7f644ebhttps://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=003ddacf1c8d869b1858181c29ea21b731a8d8d9
2024-03-25
Published