CVE-2022-48339

HIGH

GNU Emacs < 28.2 - OS Command Injection in htmlfontify.el

Title source: llm
STIX 2.1

Description

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

Scores

CVSS v3 7.8
EPSS 0.0118
EPSS Percentile 63.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-116 CWE-1116
Status published
Products (1)
gnu/emacs < 28.2
Published Feb 20, 2023
Tracked Since Feb 18, 2026