https://seclists.org/oss-sec/2026/q3/528: GNU Emacs vulnerability upon opening arbitrary file
Published Aug 20, 2026
·Updated
Affected Software
1 affected component
GNU Emacs>=undefined
Frequently Asked Questions
1
Which Emacs versions are affected?
The issue affects GNU Emacs version 28.1 and later. Gentoo reports backporting its fix as far back as Emacs 28.2.
2
What attacker interaction is required?
Exploitation is possible when a user opens an arbitrary file in Emacs. An attacker would therefore need to persuade or cause the user to open a crafted file.
3
What can be done if a fixed package is not yet available?
Disabling file-local variables is identified as an alternative mitigation and is recommended in the report. A workaround patch is also available for the Emacs 31 branch.