PT-2026-97059 · Gnu · Emacs

CVE-2026-96269

·

Published

2026-09-22

·

Updated

2026-09-24

CVSS v4.0

7.5

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GNU Emacs versions 28.1 through 31.1
Description Opening a file can lead to arbitrary code execution due to an issue where an untrusted value of read-symbol-shorthands affects the intern() and unintern() functions. This issue occurs with the default configuration and does not require specific user settings to be triggered.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96269

Affected Products

Emacs