GNU Emacs: new critical remote shell injection vulnerability.
Red Hat discovered a command injection flaw in the text editor Emacs. It allows a remote, unauthenticated attacker to execute any command on your computer. The vulnerability is activated when you visit a malicious website or link.
https://www.cve.org/CVERecord?id=CVE-2025-1244
---
#news #software #gnu #emacs #security #hacking #terminal #linux #cve #opensource #freesoftware
---
Mitigation: uninstall/update immediately.
@lxo Hi Alexandre, nice to read you again. CVE.org is a reputable site that does not distribute malware or execute unsandboxed code. It is safe to use: https://www.ssltrust.com/ssl-tools/website-security-check?domain=www.cve.org
The website does not and cannot install anything on your computer. JavaScript is used to improve the user experience.
I apologize for linking a site you can't visit due to self-imposed ethical limitations. I've attached a full-length screenshot of the page. Let me know if I can assist you further.
is javascript necessary for that website to display the required information? no
does js improve ux? maybe, but it should degrade gracefully