CVE-2024-39331
CRITICALDescription
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Is your site exposed to CVE-2024-39331?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gnu | emacs |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-39331? +
How severe is CVE-2024-39331? +
What products are affected by CVE-2024-39331? +
How do I check if I'm vulnerable to CVE-2024-39331? +
Related Vulnerabilities
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object …
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including …
Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is …
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default …
FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability …
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression …