An issue was discovered in GNU Emacs through 28.2....
Critical severity
Unreviewed
Published
Feb 21, 2023
to the GitHub Advisory Database
•
Updated Oct 7, 2023
Description
Published by the National Vulnerability Database
Feb 20, 2023
Published to the GitHub Advisory Database
Feb 21, 2023
Last updated
Oct 7, 2023
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.
References