Executive brief
Emacs TRAMP is a subsystem for remotely editing files and accessing remote systems. A local attacker can exploit a command injection flaw by crafting malicious filenames that, when processed by TRAMP, execute arbitrary code on the system. This could allow an attacker with local access to take complete control of the system if a user interacts with the malicious file.
Technical details
The vulnerability is an OS command injection (CWE-78) in Emacs TRAMP's login argument handling. TRAMP concatenates login arguments without proper sanitization before passing them to a local shell, allowing attackers to inject shell metacharacters through specially crafted filenames. The attack requires local access and user interaction—an attacker must trick a user into processing a malicious filename. Successful exploitation leads to arbitrary code execution with the privileges of the user running Emacs. A patch is expected to address this issue by implementing proper input sanitization.
Affected products
- GNU Emacs <UNKNOWN>
Timeline
- 2026-08-25: disclosed