Loading HuntDB...

GHSA-8737-h7fg-9xgj

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

Related CVEs

Key Information

GHSA ID
GHSA-8737-h7fg-9xgj
Published
November 27, 2024 3:31 PM
Last Modified
March 1, 2025 6:30 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 9, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.