THREAT OPS › Threat News › Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
<p>Posted by Sean Whitton on Sep 14</p>Bas Alberts of the GitHub Security Lab discovered that the fix for<br /> CVE-2024-53920, an arbitrary code execution flaw in Emacs, was<br /> incomplete. Viewing or editing untrusted text files in modes other than<br /> Emacs Lisp mode can also permit arbitrary code execution. For example:<br /> <br /> #!/usr/bin/perl<br /> # -*- mode: perl; mode: f
Indicators of compromise
- CVE-2024-53920cve
Original source: https://seclists.org/oss-sec/2026/q3/751