Loading HuntDB...

GHSA-hp3p-7892-f222

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

Related CVEs

Key Information

GHSA ID
GHSA-hp3p-7892-f222
Published
June 24, 2024 12:34 AM
Last Modified
July 3, 2024 6:46 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 10, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.