CVE-2024-53920Patch(gnu / emacs)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch gnu emacs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • emacs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
emacs

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-04: 1Mentions · 2026-09-14: 1Mentions · 2026-09-15: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-09-22: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-09-14: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-15: 1Technical Details · 2026-09-22: 102-0409-1409-1509-22
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-09-141
Patch1
2026-09-151
Disclosure1
2026-09-221
Patch1
Full discourse4 posts
  • OS開発者@hacker_infra
    Patch

    Emacsの脆弱性CVEが未採番だから報告したら、 Tomas Hoger commented: Hi OS開発者 We have confirmed this issue affecting emacs packages in Red Hat Enterprise Linux and started fixing process. There is not CVE assigned to this issue yet, hence we can not point you to the CVE page. Are you interested in any specific version? – Red Hat Product Security Red hatが動いた。 Message-ID: <20260921214300.4e0314a7@moche20> Date: Mon, 21 Sep 2026 21:43:00 +0200 From: Tomas Hoger <[email protected]> To: Sean Whitton <[email protected]>, Bas Alberts <[email protected]> Cc: [email protected], Eli Zaretskii <[email protected]>, Michael Albinus <[email protected]>, Stefan Monnier <[email protected]>, João Távora <[email protected]> Subject: Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 On Mon, 14 Sep 2026 11:47:17 +0100 Sean Whitton wrote: > Bas Alberts of the GitHub Security Lab discovered that the fix for > CVE-2024-53920, an arbitrary code execution flaw in Emacs, was > incomplete. Viewing or editing untrusted text files in modes other than > Emacs Lisp mode can also permit arbitrary code execution. For example: > > #!/usr/bin/perl > # -*- mode: perl; mode: flymake -*- > BEGIN { system("touch uh_oh.txt"); } > > This problem affects all Emacs versions affected by CVE-2024-53920. > This means Emacs 24 and newer, and possibly also older versions. > > A minimal fix, attached, is queued up for release with Emacs 31.2. > We (the Emacs upstream maintainers) don't expect to backport the fix to > older Emacs releases ourselves. > > This fix is more aggressive than the one we have on our master branch in > that it also implicitly disables the Eglot flymake backend. > I think we will be able to undo that before releasing Emacs 31.2, but I > wanted to get this notification out as soon as possible. > > I would be grateful if someone could assign us a CVE for this issue. Is GitHub going to assign a CVE here? I think GitHub assignment would be ok per this part of the GitHub CNA scope definition: "vulnerabilities affecting open source projects discovered by security researchers at GitHub or Microsoft not covered by another CNA’s scope." If GitHub is not doing assignment, Red Hat can provide it instead. -- Tomas Hoger / Red Hat Product Security

    Post summary

    The text discloses that the fix for CVE-2024-53920 in Emacs was incomplete, allowing arbitrary code execution via untrusted text files in non-Lisp modes; a minimal fix is queued for Emacs 31.2 and Red Hat has confirmed and begun addressing the issue.

    010201.1K
    2.9K followersView on X
  • wenlong@waynexuel
    Disclosure

    Emacs arbitrary code execution flaw (CVE-2024-53920) https://daily.cnsre.cn/en/items/6120aa73-373d-4aef-809f-2e558169f7de

    Post summary

    The text announces CVE-2024-53920 as an Emacs arbitrary code execution flaw with a link to further details, but provides limited specific information beyond the vulnerability type and CVE identifier without mentioning patches, PoCs, or exploit tools.

    0000043
    5 followersView on X
  • Repo Radar@crmingori
    Patch

    Emacs users: untrusted files can execute arbitrary code, even when viewed or edited outside Emacs Lisp mode. The original CVE-2024-53920 fix was incomplete. Emacs 24+ is affected; a minimal fix is queued for 31.2. https://lwn.net/Articles/1094224/

    Post summary

    The text discloses that Emacs is affected by an incomplete fix for CVE-2024-53920, allowing arbitrary code execution via untrusted files, and mentions a minimal fix queued for Emacs 31.2.

    0000064
    7 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    ⚠️ URGENT for Developers &amp; SysAdmins: Critical vulnerabilities (CVE-2024-53920, CVE-2025-1244) patched in Emacs for #Ubuntu 20.04/22.04/24.04 LTS. Read more: 👉 https://tinyurl.com/3r76skcy #Security https://t.co/ZOlSxf3YfL

    Post summary

    The tweet alerts developers and sysadmins that CVE‑2024‑53920 and CVE‑2025‑1244 have been patched in Emacs on Ubuntu LTS releases, urging prompt update.

    00000113
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuemacs---

Explore more