Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Users of Emacs TRAMP should avoid processing untrusted filenames or interacting with remote systems that may contain maliciously crafted file names. This operational control reduces the risk of local shell command injection.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 26 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution. | |
| Title | Emacs: local shell command injection through the user field in emacs tramp | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-26T17:56:00.585Z
Reserved: 2026-08-25T16:39:44.534Z
Link: CVE-2026-79992
Updated: 2026-08-26T17:56:00.585Z
Status : Awaiting Analysis
Published: 2026-08-25T18:18:06.973
Modified: 2026-08-28T18:58:27.140
Link: CVE-2026-79992
OpenCVE Enrichment
Updated: 2026-08-25T21:00:04Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')