GNU Emacs 28.1-31.1: Arbitrary Code Exec via read-symbol-shorthands
CVE-2026-96269 Published on September 22, 2026
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.
Vulnerability Analysis
CVE-2026-96269 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Products Associated with CVE-2026-96269
Want to know whenever a new CVE is published for GNU Emacs? stack.watch will email you.
Affected Versions
GNU Emacs:- Version 28.1, <= 31.1 is affected.