﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21139	emacs-30.1	Douglas R. Reno	Bruce Dubbs	"New minor version. This appears to be a security release:

{{{
Emacs 30.1 includes security fixes for a shell injection vulnerability
in man.el (CVE-2025-1244), and for arbitrary code execution with
flymake (CVE-2024-53920).  We recommend upgrading immediately.
}}}

Upstream is urging all users of Emacs to update immediately in the NEWS file at [https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30]

The man.el issue appears to be remotely exploitable without any authentication, and has been rated at 8.8/10. The flymake issue is rated as Medium as it requires a user to knowingly try to compile a malicious LISP file."	enhancement	closed	high	12.3	BOOK	git	medium	fixed		
