CVE-2024-53920
published 2024-11-27CVE-2024-53920: In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.53%
40.9th percentile
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-15+deb12u4 (bookworm) | emacs 1:28.2+1-15+deb12u4 (bookworm) |
| gnu | emacs | < 30.1 | 30.1 |
| gnu | emacs | >= 0 < 1:27.1+1-3.1+deb11u6 | 1:27.1+1-3.1+deb11u6 |
| gnu | emacs | >= 0 < 1:28.2+1-15+deb12u4 | 1:28.2+1-15+deb12u4 |
| gnu | emacs | >= 0 < 1:30.1+1-1 | 1:30.1+1-1 |
| gnu | emacs | >= 0 < 1:30.1+1-1 | 1:30.1+1-1 |
| gnu | emacs | >= 0 < 1:26.3+1-1ubuntu2+esm2 | 1:26.3+1-1ubuntu2+esm2 |
| gnu | emacs | >= 0 < 1:27.1+1-3ubuntu5.2+esm1 | 1:27.1+1-3ubuntu5.2+esm1 |
| gnu | emacs | >= 0 < 1:29.3+1-1ubuntu2+esm3 | 1:29.3+1-1ubuntu2+esm3 |
| msrc | azl3_emacs_29.4-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_emacs_29.4-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2026-02-04·CVSS 7.8
CVE-2025-1244 [HIGH] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Several security issues were fixed in Emacs.
It was discovered that Emacs could trigger unsafe Lisp macro expansion,
when a user invoked elisp-completion-at-point on untrusted Emacs Lisp
source code. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2024-53920)
It was discovered that Emacs did not properly sanitize input when
handling certain URI schemes. An attacker could possibly use this issue
to execute arbitrary shell commands by tricking a user into opening a
specially crafted URL. (CVE-2025-1244)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
emacs: arbitrary code execution via Lisp macro expansion
vendor_redhat·2024-11-27·CVSS 7.8
CVE-2024-53920 [HIGH] CWE-94 emacs: arbitrary code execution via Lisp macro expansion
emacs: arbitrary code execution via Lisp macro expansion
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
A flaw was found in Emacs. Viewing or editing an untrusted Emacs Lisp source code file can cause arbitrary code execution due to unsafe macro expansion when a user has configured elisp-completion-at-point for code completion or has enabled automatic error checking, such as Flymake or Flycheck.
Statement: To exploit this flaw, an attacker needs to trick a
Microsoft
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that
vendor_msrc·2024-11-12·CVSS 7.8
CVE-2024-53920 [HIGH] CWE-94 In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparen
Debian
CVE-2024-53920: emacs - In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-co...
vendor_debian·2024·CVSS 7.8
CVE-2024-53920 [HIGH] CVE-2024-53920: emacs - In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-co...
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
Scope: local
bookworm: resolved (fixed in 1:28.2+1-15+deb12u4)
bullseye: resolved (fixed in 1:27.1+1-3.1+deb11u6)
forky: resolved (fixed in 1:30.1+1-1)
sid: resolved (fixed in 1:30.1+1-1)
trixie: resolved (fixed in 1:30.1+1-1)
OSV
emacs vulnerabilities
osv·2026-02-04·CVSS 7.8
CVE-2024-53920 [HIGH] emacs vulnerabilities
emacs vulnerabilities
It was discovered that Emacs could trigger unsafe Lisp macro expansion,
when a user invoked elisp-completion-at-point on untrusted Emacs Lisp
source code. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2024-53920)
It was discovered that Emacs did not properly sanitize input when
handling certain URI schemes. An attacker could possibly use this issue
to execute arbitrary shell commands by tricking a user into opening a
specially crafted URL. (CVE-2025-1244)
OSV
CVE-2024-53920: In elisp-mode
osv·2024-11-27·CVSS 7.8
CVE-2024-53920 [HIGH] CVE-2024-53920: In elisp-mode
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
GHSA
GHSA-8737-h7fg-9xgj: In elisp-mode
ghsa_unreviewed·2024-11-27
CVE-2024-53920 [CRITICAL] CWE-94 GHSA-8737-h7fg-9xgj: In elisp-mode
In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
No detection rules found.
No public exploits indexed.
https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.htmlhttps://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1https://news.ycombinator.com/item?id=42256409https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg@mail.gmail.com/https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html
2024-11-27
Published