CVE-2024-53920

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*

History

03 Nov 2025, 21:17

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html -

Information

Published : 2024-11-27 15:15

Updated : 2025-11-03 21:17


NVD link : CVE-2024-53920

Mitre link : CVE-2024-53920

CVE.ORG link : CVE-2024-53920


JSON object : View

Products Affected

gnu

  • emacs
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')