First published: Mon Mar 25 2024(Updated: )
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Emacs | <29.3 | |
Gnu Org Mode | <9.6.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30202 has not been assigned a specific severity rating, but it allows for arbitrary code execution in vulnerable versions of Emacs and Org Mode.
To fix CVE-2024-30202, upgrade Emacs to version 29.3 or higher and Org Mode to version 9.6.23 or higher.
CVE-2024-30202 affects GNU Emacs versions before 29.3 and GNU Org Mode versions before 9.6.23.
CVE-2024-30202 is a code execution vulnerability caused by evaluating arbitrary Lisp code in Emacs when Org mode is enabled.
Users of GNU Emacs and Org Mode prior to the specified versions are at risk due to CVE-2024-30202.