Change History (4)
comment:1 by , 10 months ago
comment:3 by , 9 months ago
Priority: | normal → elevated |
---|
More details for the security advisory:
Hi, Here is a vulnerability in Emacs Org mode. Reproducer is the following .org file: #+LINK: shell %(shell-command-to-string) [[shell:touch ~/hacked.txt]] When sent by email and previewed in Emacs or when opened in Emacs as a file, the above Org file will evaluate "touch ~/hacked.txt" without any prompts.
Note:
See TracTickets
for help on using tickets.
Changes in Emacs 29.4 Emacs 29.4 is an emergency bugfix release intended to fix the security vulnerability described below.
This is for security reasons, to avoid running malicious commands.