CVE-2024-53920

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-27 15:15

Updated : 2025-11-03 21:17


NVD link : CVE-2024-53920

Mitre link : CVE-2024-53920

CVE.ORG link : CVE-2024-53920


JSON object : View

Products Affected

gnu

  • emacs
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')