CVE-2023-27986 describes an Emacs Lisp code injection vulnerability in Emacs versions 28.1 through 28.2, specifically affecting the emacsclient-mail.desktop component. This flaw allows an attacker to execute arbitrary code by crafting a malicious mailto: URI containing unescaped double-quote characters. With a CVSS score of 7.8 (HIGH), the vulnerability requires user interaction (UI:R) and local access (AV:L), but successful exploitation can lead to high confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 28.1, <= 28.2CPE matchmatch criteria | cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
Mar 14, 2023emacs: Emacs Lisp code injection via a crafted mailto URI
Mar 8, 2023