CVE-2026-96269
— UNSCOREDPublished 2026-09-22 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.
Weaknesses
CWE-829
All references
- https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80574#227
- https://yhetil.org/emacs/jwvtsph1aoj.fsf-monnier+emacs@gnu.org/T/#m319545e835fb71d764bf868166632d4633167a75
- https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html
- https://www.openwall.com/lists/oss-security/2026/08/20/3
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-17647
- UNSCOREDCVE-2026-47781PoC
- LOWCVE-2026-49449PoC
- HIGHCVE-2026-54160PoC
- CRITICALCVE-2026-66902PoC
- HIGHCVE-2026-67623PoC
- MEDIUMCVE-2026-81305PoC
- UNSCOREDCVE-2026-86131
Related by shared AI tags and CWE weakness class. Browse the full archive.