REDHAT-BUG-2523665: Command Injection
Published Aug 25, 2026
·Updated
Emacs TRAMP is vulnerable to a local shell command injection when processing maliciously crafted filenames. The vulnerability arises from the fact of TRAMP concatenating login arguments without a proper sanitization and further passing the result into a local shell.
Affected Software
1 affected component
Emacs TRAMP
Event History
Aug 25, 2026
Data Sourced
via Red Hat·04:52 PM
DescriptionSeverityAffected Software