CVE-2024-30205
published 2024-03-25CVE-2024-30205: In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
PriorityP427high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
0.48%
38.3th percentile
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | emacs | < emacs 1:28.2+1-15+deb12u1 (bookworm) | emacs 1:28.2+1-15+deb12u1 (bookworm) |
| debian | org-mode | < emacs 1:28.2+1-15+deb12u1 (bookworm) | emacs 1:28.2+1-15+deb12u1 (bookworm) |
| gnu | emacs | < 29.3 | 29.3 |
| gnu | emacs | >= 0 < 1:27.1+1-3.1+deb11u3 | 1:27.1+1-3.1+deb11u3 |
| gnu | emacs | >= 0 < 1:28.2+1-15+deb12u1 | 1:28.2+1-15+deb12u1 |
| gnu | emacs | >= 0 < 1:29.3+1-1 | 1:29.3+1-1 |
| gnu | emacs | >= 0 < 1:29.3+1-1 | 1:29.3+1-1 |
| gnu | emacs | >= 0 < 1:27.1+1-3ubuntu5.2 | 1:27.1+1-3ubuntu5.2 |
| gnu | emacs | >= 0 < 1:26.3+1-1ubuntu2+esm1 | 1:26.3+1-1ubuntu2+esm1 |
| gnu | emacs | >= 0 < 1:29.3+1-1ubuntu2+esm1 | 1:29.3+1-1ubuntu2+esm1 |
| gnu | org_mode | < 9.6.23 | 9.6.23 |
| msrc | azl3_emacs_29.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_emacs_29.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_emacs_28.2-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_emacs_29.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Org Mode vulnerabilities
vendor_ubuntu·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] Org Mode vulnerabilities
Title: Org Mode vulnerabilities
Summary: Several security issues were fixed in Org Mode.
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This iss
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2024-09-19·CVSS 7.8
CVE-2024-39331 [HIGH] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Several security issues were fixed in Emacs.
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discov
Red Hat
emacs: Org mode considers contents of remote files to be trusted
vendor_redhat·2024-03-25·CVSS 7.1
CVE-2024-30205 [HIGH] CWE-349 emacs: Org mode considers contents of remote files to be trusted
emacs: Org mode considers contents of remote files to be trusted
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
A flaw was found in Emacs. Org mode considers the content of remote files, such as files opened with TRAMP on remote systems, to be trusted, resulting in arbitrary code execution.
Statement: To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file from a remote system. For this reason, this flaw has been rated with a Moderate security impact.
Mitigation: Do not open untrusted Org mode files from a remote system.
Package: emacs (Red Hat Enterprise Linux 10) - Affected
Package: emacs (Red Hat Enterprise Linux 6) - Out of support scope
Package: emacs (Red Hat Enterprise
Microsoft
In Emacs before 29.3 Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
vendor_msrc·2024-03-12·CVSS 7.1
CVE-2024-30205 [HIGH] CWE-494 In Emacs before 29.3 Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
In Emacs before 29.3 Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2024-30205: emacs - In Emacs before 29.3, Org mode considers contents of remote files to be trusted....
vendor_debian·2024·CVSS 7.1
CVE-2024-30205 [HIGH] CVE-2024-30205: emacs - In Emacs before 29.3, Org mode considers contents of remote files to be trusted....
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-15+deb12u1)
bullseye: resolved (fixed in 1:27.1+1-3.1+deb11u3)
forky: resolved (fixed in 1:29.3+1-1)
sid: resolved (fixed in 1:29.3+1-1)
trixie: resolved (fixed in 1:29.3+1-1)
OSV
org-mode vulnerabilities
osv·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] org-mode vulnerabilities
org-mode vulnerabilities
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
OSV
emacs, emacs24, emacs25 vulnerabilities
osv·2024-09-19·CVSS 7.8
CVE-2022-45939 [HIGH] emacs, emacs24, emacs25 vulnerabilities
emacs, emacs24, emacs25 vulnerabilities
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discovered that Emacs incorrectly handled input sa
OSV
CVE-2024-30205: In Emacs before 29
osv·2024-03-25·CVSS 7.1
CVE-2024-30205 [HIGH] CVE-2024-30205: In Emacs before 29
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
GHSA
GHSA-vxx9-qwhq-hgf4: In Emacs before 29
ghsa_unreviewed·2024-03-25
CVE-2024-30205 [HIGH] CWE-494 GHSA-vxx9-qwhq-hgf4: In Emacs before 29
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/03/25/2https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=2bc865ace050ff118db43f01457f95f95112b877https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=4255d5dcc0657915f90e4fba7e0a5514cced514dhttps://lists.debian.org/debian-lts-announce/2024/04/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/04/msg00024.htmlhttp://www.openwall.com/lists/oss-security/2024/03/25/2https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=2bc865ace050ff118db43f01457f95f95112b877https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=4255d5dcc0657915f90e4fba7e0a5514cced514dhttps://lists.debian.org/debian-lts-announce/2024/04/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/04/msg00024.html
2024-03-25
Published