Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-79992— Emacs: local shell command injection through the user field in emacs tramp

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

发现 Emacs TRAMP 存在一处漏洞。本地攻击者可通过处理恶意构造的文件名利用此漏洞。该问题源于 TRAMP 在拼接登录参数时未进行适当 sanitization(清理/过滤),随后将这些参数传递给本地 shell 执行。成功利用此漏洞可能导致任意代码执行。

CVSS 7.8 · High

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 5

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79992

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Emacs: local shell command injection through the user field in emacs tramp
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-79992

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79992

登录查看更多情报信息。

Vendor Advisories for CVE-2026-79992 (1)

Other References for CVE-2026-79992 (1)

Same Patch Batch · Red Hat · 2026-08-25 · 10 CVEs total

CVE-2026-79655 7.8 HIGH Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targ
CVE-2026-80186 7.6 HIGH Bluez: stack overflow in name2utf8 causes dos and potential code execution
CVE-2026-78701 6.5 MEDIUM 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall d
CVE-2026-78322 6.5 MEDIUM File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar hand
CVE-2026-79717 6.4 MEDIUM Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restrict
CVE-2026-79652 5.9 MEDIUM Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce cons
CVE-2026-80185 5.7 MEDIUM Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary cod
CVE-2026-77680 5.3 MEDIUM Libsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025
CVE-2026-80101 4.4 MEDIUM Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-l

IV. Related Vulnerabilities

V. Comments for CVE-2026-79992

No comments yet


Leave a comment