A newly disclosed GNU Emacs vulnerability allows arbitrary code execution when a user opens a malicious file, affecting Emacs 28.1 and later. The issue was reported by researcher Eshel Yaron and discussed on both oss-sec and emacs-devel, where maintainers treated it as serious enough to factor into Emacs 31 release decisions. The flaw is tied to unsafe handling of read-symbol-shorthands around risky intern calls, with discussion highlighting the VC-related attack path as one of the easiest ways to trigger the bug.
Upstream published a workaround patch for the Emacs 31 branch and committed a broader rework on master, while Gentoo backported fixes that nullify read-symbol-shorthands around vulnerable code paths and shipped updated packages for 28.2, 29.4, and 30.2. Gentoo later issued GLSA-202608-18, and Tenable released a Nessus detection plugin for affected Gentoo installations. As an interim mitigation, users were advised to disable file-local variables if they cannot immediately apply patched versions.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Tenable published Nessus plugin 338227 to detect Gentoo systems affected by the GNU Emacs arbitrary code execution issue described in GLSA-202608-18. The plugin performs a version check rather than active exploitation testing.
Gentoo published GLSA-202608-18 covering the GNU Emacs arbitrary code execution vulnerability and advising upgrades to fixed package versions for Emacs 28, 29, and 30. The advisory formalized distribution guidance for Gentoo users affected by bug 980616.
Sam James disclosed a GNU Emacs arbitrary code execution vulnerability on oss-sec, stating it can be triggered when a user opens an arbitrary file and affects Emacs 28.1 and later. The disclosure also noted upstream discussion, available fixes, and Gentoo backports.
Ulrich Müller committed change 7f209a587c7d2ec40600e490010ac0c5d900f869 to remove older Emacs package versions from the Gentoo repository. This followed the packaging of patched releases for the arbitrary code execution issue.
Ulrich Müller committed repository change 30a49a0ad1daa9eae5498e96d706387831fae2d2 updating Gentoo Emacs packages to patched versions 28.2-r21, 29.4-r9, and 30.2-r5. The commit referenced both Gentoo bug 980616 and GNU debbugs issue 80574.
Ulrich Müller committed Gentoo patch set cbb5193325aa9523646c629194fc1e7034990b8f to mitigate the Emacs flaw by nullifying read-symbol-shorthands around risky intern calls. Gentoo applied the fixes to its emacs-patches repository for supported package branches.
Eshel Yaron published a public write-up describing the GNU Emacs arbitrary code execution vulnerability. Later references tied this write-up to the issue affecting Emacs 28.1 and later.
Eshel Yaron described a patch to bind read-symbol-shorthands to nil around VC-related code as a mitigation for the arbitrary code execution issue. The thread also discussed broader fixes, including an intern--without-shorthands helper and root-cause remediation on master.
In an emacs-devel thread, Eshel Yaron urged maintainers to wait for mitigation of bug #80574, calling it a serious security concern that should be fixed before Emacs 31 shipped. The discussion framed the vulnerability as important enough to potentially block release.
Alan Coopersmith announced GNU Emacs 30.1, which fixed two security issues: shell injection flaw CVE-2025-1244 and arbitrary code execution flaw CVE-2024-53920. The release also introduced mitigations such as the new trusted-content option and disabling elisp-flymake-byte-compile for untrusted files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcebugs.gentoo.org
Open sourcetenable.com
Open sourcelists.gnu.org
Open sourceopenwall.com
Open sourcecgit.git.savannah.gnu.org
Open sourcecgit.git.savannah.gnu.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.