CVE-2024-53920
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- gnu/emacs
- Source
- cve@mitre.org
References
- https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.htmlThird Party Advisory
- https://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92Product
- https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4Release Notes
- https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1Product
- https://news.ycombinator.com/item?id=42256409Issue Tracking
- https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg@mail.gmail.com/Mailing List
- http://www.openwall.com/lists/oss-security/2026/08/20/3
- http://www.openwall.com/lists/oss-security/2026/08/20/7
- https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.