CVE-2024-39331
published 2024-06-23CVE-2024-39331: In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.31%
67.5th percentile
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-15+deb12u3 (bookworm) | emacs 1:28.2+1-15+deb12u3 (bookworm) |
| debian | org-mode | < emacs 1:28.2+1-15+deb12u3 (bookworm) | emacs 1:28.2+1-15+deb12u3 (bookworm) |
| gnu | emacs | < 29.4 | 29.4 |
| gnu | emacs | >= 0 < 1:27.1+1-3.1+deb11u5 | 1:27.1+1-3.1+deb11u5 |
| gnu | emacs | >= 0 < 1:28.2+1-15+deb12u3 | 1:28.2+1-15+deb12u3 |
| gnu | emacs | >= 0 < 1:29.4+1-1 | 1:29.4+1-1 |
| gnu | emacs | >= 0 < 1:29.4+1-1 | 1:29.4+1-1 |
| gnu | emacs | >= 0 < 1:27.1+1-3ubuntu5.2 | 1:27.1+1-3ubuntu5.2 |
| gnu | emacs | >= 0 < 1:26.3+1-1ubuntu2+esm1 | 1:26.3+1-1ubuntu2+esm1 |
| gnu | emacs | >= 0 < 1:29.3+1-1ubuntu2+esm1 | 1:29.3+1-1ubuntu2+esm1 |
| msrc | azl3_emacs_29.3-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_emacs_29.4-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_emacs_29.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_emacs_29.4-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Org Mode vulnerabilities
vendor_ubuntu·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] Org Mode vulnerabilities
Title: Org Mode vulnerabilities
Summary: Several security issues were fixed in Org Mode.
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This iss
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2024-09-19·CVSS 7.8
CVE-2024-39331 [HIGH] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Several security issues were fixed in Emacs.
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discov
Red Hat
emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code
vendor_redhat·2024-06-23·CVSS 9.8
CVE-2024-39331 [CRITICAL] CWE-95 emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code
emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
A flaw was found in Emacs. Arbitrary shell commands can be executed without prompting when an Org mode file is opened or when the Org mode is enabled, when Emacs is used as an email client, this issue can be triggered when previewing email attachments.
Statement: To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file or previewing a crafted email attachment. For this reason, this flaw has been rated with a Moderate security impact.
Mitigation: Do not open Org mode files or previ
Microsoft
In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function such as shell-command-to-string. This affects Org Mode before 9.7.5.
vendor_msrc·2024-06-11·CVSS 9.8
CVE-2024-39331 [CRITICAL] CWE-94 In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function such as shell-command-to-string. This affects Org Mode before 9.7.5.
In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function such as shell-command-to-string. This affects Org Mode before 9.7.5.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CV
Debian
CVE-2024-39331: emacs - In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link...
vendor_debian·2024·CVSS 9.8
CVE-2024-39331 [CRITICAL] CVE-2024-39331: emacs - In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link...
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-15+deb12u3)
bullseye: resolved (fixed in 1:27.1+1-3.1+deb11u5)
forky: resolved (fixed in 1:29.4+1-1)
sid: resolved (fixed in 1:29.4+1-1)
trixie: resolved (fixed in 1:29.4+1-1)
OSV
org-mode vulnerabilities
osv·2025-03-27·CVSS 7.8
CVE-2023-28617 [HIGH] org-mode vulnerabilities
org-mode vulnerabilities
It was discovered that Org Mode did not correctly handle filenames
containing shell metacharacters. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its
buffer. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of
remote files. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
OSV
emacs, emacs24, emacs25 vulnerabilities
osv·2024-09-19·CVSS 7.8
CVE-2022-45939 [HIGH] emacs, emacs24, emacs25 vulnerabilities
emacs, emacs24, emacs25 vulnerabilities
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discovered that Emacs incorrectly handled input sa
GHSA
GHSA-hp3p-7892-f222: In Emacs before 29
ghsa_unreviewed·2024-06-24
CVE-2024-39331 [CRITICAL] CWE-94 GHSA-hp3p-7892-f222: In Emacs before 29
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
OSV
CVE-2024-39331: In Emacs before 29
osv·2024-06-23·CVSS 9.8
CVE-2024-39331 [CRITICAL] CVE-2024-39331: In Emacs before 29
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8https://list.orgmode.org/87sex5gdqc.fsf%40localhost/https://lists.debian.org/debian-lts-announce/2024/06/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00024.htmlhttps://lists.gnu.org/archive/html/info-gnu-emacs/2024-06/msg00000.htmlhttps://news.ycombinator.com/item?id=40768225https://www.openwall.com/lists/oss-security/2024/06/23/1https://www.openwall.com/lists/oss-security/2024/06/23/2https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8https://list.orgmode.org/87sex5gdqc.fsf%40localhost/https://lists.debian.org/debian-lts-announce/2024/06/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00024.htmlhttps://lists.gnu.org/archive/html/info-gnu-emacs/2024-06/msg00000.htmlhttps://news.ycombinator.com/item?id=40768225https://www.openwall.com/lists/oss-security/2024/06/23/1https://www.openwall.com/lists/oss-security/2024/06/23/2
2024-06-23
Published