A critical flaw in GNU Emacs TRAMP can lead to local command execution when Emacs processes specially crafted file names, symlink targets, or remote-style paths. The issue stems from shell command injection in the TRAMP user field, where login arguments are concatenated without proper quoting and passed to a local shell during connection setup. A second weakness in TRAMP file name dispatch uses line anchoring instead of full-string anchoring, allowing embedded "/ssh:..." substrings inside otherwise ordinary paths to reach the vulnerable code path before any real SSH connection is established.
The bug was disclosed on the oss-sec mailing list by Sean Whitton, crediting Bas Alberts of GitHub Security Lab for discovery and Michael Albinus for the fix. Discussion on the thread indicated the upstream fix is expected in Emacs 31, while Gentoo has already backported patches for multiple releases, including 27.2, 28.2, 29.4, 30.2, and 31.1_rc1. Gentoo also issued GLSA-202608-21, and Tenable published Nessus plugin 339063 to identify affected Emacs installations on Gentoo through version checks, with upgrades recommended for supported 27, 28, 29, and 30 branches.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Sean Whitton announced that the GNU Emacs TRAMP zero-click local command-execution vulnerability was assigned CVE-2026-79992. The notice identifies Emacs 30.2 and later as affected, while noting earlier versions may also be vulnerable.
Tenable published Nessus plugin 339063 to detect Gentoo systems affected by GLSA-202608-21. The plugin is rated High severity and checks self-reported package versions instead of attempting exploitation.
Gentoo published GLSA-202608-21 covering an arbitrary code execution vulnerability in GNU Emacs and recommended fixed package versions for branches 27 through 30. Tenable's Nessus plugin entry reflects the advisory and notes detection is version-based rather than exploit-based.
Sam James reported that Gentoo had already backported downstream patches for Emacs 27.2, 28.2, 29.4, 30.2, and 31.1_rc1 for the TRAMP issue. He also said he believed the vulnerability would be fixed in Emacs 31.
A follow-up reply in the oss-sec thread stated that Emacs does not have separate security releases and asked whether the TRAMP issue would be fixed in Emacs 31. The message reflected ongoing public discussion of remediation plans rather than a confirmed upstream fix.
Sean Whitton disclosed a critical GNU Emacs TRAMP local command execution vulnerability on the oss-sec mailing list, crediting Bas Alberts of GitHub Security Lab for discovering it. The disclosure described command injection via the TRAMP user field and a file name dispatch flaw that could trigger execution from crafted paths or symlink targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcetenable.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.