GHSA-8737-h7fg-9xgj
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: August 9, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.