Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-45939

25
FAUCET Score

CVE-2022-45939 is a critical vulnerability in GNU Emacs up to version 28.2, affecting Debian, Fedora, and GNU Emacs distributions. It allows attackers to execute arbitrary commands by embedding shell metacharacters in source-code filenames, which are then processed by the vulnerable ctags program. This vulnerability carries a high CVSS score of 7.8, indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability, typically requiring user interaction. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 28.2CPE matchmatch criteria
cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 45th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: cbl2 emacs 28.1-5 on CBL Mariner 2.0Fixed in: 28.1-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 28.1-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 28.1-5
microsoftpatch availablevia msrc
Product: 19512-16823Fixed in: 28.1-5
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: emacs-1:27.2-8.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: emacs-1:26.1-9.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: emacs-1:26.1-7.el8_6.3
View patch

Vendor Advisories (3)

microsoft2022-Dec/CVE-2022-45939

CVE-2022-45939

Dec 13, 2022
redhatCVE-2022-45939Moderate

emacs: ctags local command execution vulnerability

Nov 27, 2022
microsoft2022-Nov/CVE-2022-45939Important

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input.

Nov 8, 2022

References

git.savannah.gnu.org / cgit/emacs.git/commit
Patch
lists.debian.org / debian-lts-announce/2022/12/msg00046.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FOSK3J7BBAEI4IITW2DRUKLQYUZYKH6Y
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GOXIH2FDEQJEAARE52C3GHTLGQFBYPIB
debian.org / security/2023/dsa-5314
Third Party Advisory