{"id":"CVE-2025-1244","title":"A command injection flaw was found in the text editor Emacs","summary":"A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a special…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"published":"2025-02-12","updated":"2026-06-26","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-1244","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:1915","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1917","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1961","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1962","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1963","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:1964","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2022","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2130","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2157","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2195","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:2754","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-1244","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2345150","label":"secalert@redhat.com"},{"url":"https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=820f0793f0b46448928905552726c1f1b999062f","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2025/03/01/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://debbugs.gnu.org/cgi/bugreport.cgi?bug=66390","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02632,"epssPercentile":0.84872,"ingestedAt":"2026-06-26T16:43:13.408Z","slug":"CVE-2025-1244","body":"## Overview\n\nA command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}