Impact
A flaw in the Emacs text editor allows the Fit‑make mode to execute code supplied by the edited file when the language backend is not Lisp. The execution occurs during syntax checking, giving the running user the ability to run arbitrary code from the file. This flaw maps to the input evaluation weakness CWE‑94 and can compromise confidentiality, integrity, and availability of the user’s environment.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8 and 9 users of Emacs versions before 31.2 are affected. The vulnerability manifests when the user opens or edits a file under Emacs that is processed by Flymake with a non‑Lisp backend.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. Exploitation requires that an attacker supply or influence a file that Emacs processes locally, so a privileged or local attacker can trigger the flaw by opening or editing a crafted file. EPSS data is absent, and the vulnerability is not listed in CISA KEV, but the high CVSS suggests the risk is significant for environments where untrusted files may be opened by privileged users.
OpenCVE Enrichment