📦

emacs

Vendor: gnu

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 14 Remote Access
Total CVEs 343 Total Indexed
Avg. EPSS 1.33% Exploit Prob.
Latest CVE CVE-2026-6861 Apr 22

Security Vulnerability Index

Page 1 / 35
6.1 CVSS

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.

EPSS: 0.11%
7.8 CVSS

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

EPSS: 0.53%
9.8 CVSS

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

EPSS: 1.31%
7.1 CVSS

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

EPSS: 0.48%
2.8 CVSS

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

EPSS: 0.47%
5.5 CVSS

In Emacs before 29.3, Gnus treats inline MIME contents as trusted.

EPSS: 0.58%
7.8 CVSS

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

EPSS: 1.10%
7.8 CVSS

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

EPSS: 0.46%
7.8 CVSS

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

EPSS: 0.48%
7.8 CVSS

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

EPSS: 1.09%