CVE-2025-1244

Executive Summary

CVE-2025-1244 reveals a command‑injection flaw in GNU Emacs that lets unauthenticated remote attackers run arbitrary shell commands by tricking users into visiting a malicious URL or HTTP redirect. The vulnerability can lead to full system compromise on affected installations. No KEV listing yet; mitigate by updating to the latest Emacs release or disabling network features.


Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2025-02-12T15:15:18.430 - Last Modified: 2026-09-06T02:17:16.397

Original Description: A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

"You get peace of mind not by thinking about it or imagining it, but by quietening and relaxing the restless mind."

— Remez Sasson
Source: NVD