CVE-1999-0114

Elm 2.4 - Local Command Execution and File Read via Filter Command Symlink Attack

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0114. PoCs published by HORKimhab.

AI-analyzed exploit summary The repository contains a placeholder markdown file for CVE-1999-0114, describing a symlink attack vulnerability in Elm elm-2.4 mail package that allows local users to execute commands or read files as other users. However, no functional exploit code or technical details are provided.

Description

Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.

Exploits (1)

github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/1999/0xxx/CVE-1999-0114.md

The repository contains a placeholder markdown file for CVE-1999-0114, describing a symlink attack vulnerability in Elm elm-2.4 mail package that allows local users to execute commands or read files as other users. However, no functional exploit code or technical details are provided.

Classification
Stub 95%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Elm elm-2.4 mail package
Auth required
Prerequisites: Local access to the target system · Vulnerable version of Elm elm-2.4 installed
mistral-large-3 · analyzed Jul 15, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0114

Scores

EPSS 0.0082
EPSS Percentile 53.5%

Details

Status published
Products (1)
elm_development_group/elm 2.4
Published Jan 01, 1998
Tracked Since Feb 18, 2026