Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-48339


An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.


Published

2023-02-20T23:15:12.350

Last Modified

2025-03-18T16:15:15.070

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-116
  • Type: Secondary
    CWE-1116

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnu emacs ≤ 28.2 Yes

References