No advisories yet.
Solution
No solution given by the vendor.
Workaround
Users of Emacs TRAMP should avoid processing untrusted filenames or interacting with remote systems that may contain maliciously crafted file names. This operational control reduces the risk of local shell command injection.
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution. | |
| Title | Emacs: local shell command injection through the user field in emacs tramp | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-25T17:44:28.008Z
Reserved: 2026-08-25T16:39:44.534Z
Link: CVE-2026-79992
Updated: 2026-08-25T17:38:56.201Z
Status : Received
Published: 2026-08-25T18:18:06.973
Modified: 2026-08-25T18:18:06.973
Link: CVE-2026-79992
No data.
OpenCVE Enrichment
No data.