CVE-2024-30205
Emacs vulnerability analysis and mitigation

Overview

CVE-2024-30205 affects Emacs versions before 29.3 and Org Mode versions before 9.6.23, where Org mode incorrectly considers contents of remote files to be trusted. The vulnerability was disclosed on March 25, 2024, and affects the security of Emacs text editor and its Org mode component (NVD, Debian LTS).

Technical details

The vulnerability stems from a security design flaw where Org mode treats remote files, including those accessed through TRAMP (Transparent Remote Access, Multiple Protocol), as trusted content. This behavior could potentially allow malicious remote content to be executed with the same trust level as local files. The issue has been assigned a CVSS v3.1 base score of 7.1 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H, indicating local access vector with low attack complexity and no privileges required but user interaction needed (NVD).

Impact

The vulnerability could allow an attacker to execute malicious code through remote files that are treated as trusted by Org mode. This could lead to unauthorized code execution within the context of the user's Emacs session when opening remote files or accessing content through TRAMP (Emacs Commit).

Exploitability

The vulnerability requires user interaction in the form of opening a malicious remote file in Org mode. The attack vector is local, meaning the attacker needs to convince the user to open a specially crafted remote file. The vulnerability has been classified with a CWE-494 (Download of Code Without Integrity Check) designation (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Emacs 29.3 and Org Mode 9.6.23. The fix involves treating all remote files as untrusted by default by implementing additional checks using the file-remote-p function. Users are strongly recommended to upgrade to these versions or later. For systems that cannot be immediately upgraded, the safest workaround is to avoid opening untrusted remote files in Org mode (Org Mode Commit, Debian LTS).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

org-mode

Affected

bullseye

org-mode: 9.4.0+dfsg-1+deb11u2

Fixed

sid

org-mode: 9.6.23+dfsg-1

Fixed

trixie

org-mode: 9.6.23+dfsg-1

Fixed

SourceThis report was generated using AI

Related Emacs vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79992HIGH7.8
  • Emacs logoEmacs
  • emacs
NoYesAug 25, 2026
CVE-2026-77219MEDIUM6.9
  • Emacs logoEmacs
  • emacs-gtk+x11-debuginfo
NoYesAug 21, 2026
CVE-2026-71394MEDIUM5.3
  • Emacs logoEmacs
  • xemacs21-packages
NoYesAug 10, 2026
CVE-2026-71393MEDIUM5.3
  • Emacs logoEmacs
  • cpe:2.3:a:gnu:emacs
NoYesAug 10, 2026
CVE-2026-71392MEDIUM5.3
  • Emacs logoEmacs
  • emacs25
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management