A vulnerability has been discovered in GNU Emacs allowing arbitrary code execution. Affected packages Package app-editors/emacs on all architectures Affected versions < 27.2-r4 < 28.2-r22 < 29.4-r10 < 30.2-r6 Unaffected versions >= 27.2-r4 >= 28.2-r22 >= 29.4-r10 >= 30.2-r6 Background GNU Emacs is the extensible, customizable, self-documenting real-time display editor. Description A vulnerability has been discovered in GNU Emacs. Please review the CVE identifier referenced below for details. Impact An attacker could achieve arbitrary code execution by tricking a user into opening a file or directory with a malicious filename via TRAMP. Workaround There is no known workaround at this time. Resolution All GNU Emacs 27 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-27.2-r4:27" All GNU Emacs 28 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r22:28" All GNU Emacs 29 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r10:29" All GNU Emacs 30 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r6:30" References Release date August 24, 2026 Latest revision August 24, 2026: 1 Severity high Exploitable local and remote Bugzilla entries 981157
A high-severity vulnerability (CVSS not provided) in GNU Emacs allows arbitrary code execution when a user is tricked into opening a file or directory with a malicious filename via TRAMP. Affected versions are Emacs 27 prior to 27.2-r4, 28 prior to 28.2-r22, 29 prior to 29.4-r10, and 30 prior to 30.2-r6. The resolution is to upgrade to the specific fixed versions listed, as no workaround is currently available.