Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, users should avoid opening or editing untrusted text files with Emacs. Exercise caution when handling files from unknown or suspicious sources, as interacting with them can lead to arbitrary code execution.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920 | Emacs: emacs: arbitrary code execution in flymake mode |
Thu, 24 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu emacs |
|
| Vendors & Products |
Gnu
Gnu emacs |
Wed, 23 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or editing untrusted files using Emacs could lead to arbitrary code execution with the privileges of the user running Emacs. | |
| Title | Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920 | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-24T10:31:35.864Z
Reserved: 2026-09-23T08:58:32.822Z
Link: CVE-2026-96442
Updated: 2026-09-23T13:55:15.446Z
Status : Awaiting Analysis
Published: 2026-09-23T11:17:18.550
Modified: 2026-09-23T19:40:10.000
Link: CVE-2026-96442
OpenCVE Enrichment
Updated: 2026-09-24T09:11:23Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')