{"id":"CVE-2025-1244","summary":"Emacs: shell injection vulnerability in gnu emacs via custom \"man\" uri scheme","details":"A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.","modified":"2026-09-12T11:30:39.423421425Z","published":"2025-02-12T14:27:45.707Z","related":["ALSA-2025:1915","ALSA-2025:1917","SUSE-SU-2025:0574-1","SUSE-SU-2025:0589-1","SUSE-SU-2025:0599-1","openSUSE-SU-2025:14767-1"],"database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1244.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"29.4.0"}]}],"cna_assigner":"redhat"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/01/2"},{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"WEB","url":"https://debbugs.gnu.org/cgi/bugreport.cgi?bug=66390"},{"type":"WEB","url":"https://git.savannah.gnu.org/cgit/emacs.git/"},{"type":"WEB","url":"https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=820f0793f0b46448928905552726c1f1b999062f"},{"type":"WEB","url":"https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:1915"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:1917"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:1961"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:1962"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:1963"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:1964"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:2022"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:2130"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:2157"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:2195"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:2754"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-1244"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1244.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1244"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2345150"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://cgit.git.savannah.gnu.org/cgit/emacs.git","events":[{"introduced":"0"},{"fixed":"820f0793f0b46448928905552726c1f1b999062f"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-1244.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}