CVE-2023-28617
Emacs vulnerability analysis and mitigation

Overview

CVE-2023-28617 affects org-babel-execute:latex in ob-latex.el in Org Mode through version 9.6.1 for GNU Emacs. The vulnerability was discovered by Xi Lu and allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters (NVD).

Technical details

The vulnerability exists in the org-babel-execute:latex function within ob-latex.el, where shell commands were used to move files without proper input sanitization. The issue has a CVSS v3.1 Base Score of 7.8 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local access is required but no privileges are needed (NVD).

Impact

The vulnerability allows attackers to execute arbitrary shell commands through specially crafted file or directory names containing shell metacharacters, potentially leading to system compromise with the privileges of the Emacs process (Debian Security).

Mitigation and workarounds

The vulnerability was fixed in Org Mode version 9.6.2 by replacing shell commands with the Emacs built-in rename-file function. Various distributions have released security updates: Debian 10 (version 1:26.1+1-3.2+deb10u4), Ubuntu (multiple versions), and Red Hat Enterprise Linux 8 (Debian Security, Org Mode Patch).

Additional resources


SourceThis report was generated using AI

Related Emacs vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-39331CRITICAL9.8
  • EmacsEmacs
  • cpe:2.3:a:gnu:emacs
NoYesJun 23, 2024
CVE-2025-1244HIGH8.8
  • EmacsEmacs
  • emacs-nw-debuginfo
NoYesFeb 12, 2025
CVE-2024-53920HIGH7.8
  • EmacsEmacs
  • emacs-devel
NoYesNov 27, 2024
CVE-2024-30205HIGH7.1
  • EmacsEmacs
  • emacs-debuginfo
NoYesMar 25, 2024
CVE-2024-30204LOW2.8
  • EmacsEmacs
  • app-emacs/org-mode
NoYesMar 25, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management