Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39658
HistoryMar 11, 2023 - 7:20 p.m.

Command Injection

2023-03-1119:20:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
emacs
vulnerability
command injection
input parameters
escape
hfy-istext-command
attacker
malicious commands
file name
directory name
shell metacharacters
software

0.001 Low

EPSS

Percentile

25.1%

emacs is vulnerable to Command Injection. The vulnerability exists because the input parameters are not properly escaped in the hfy-istext-command function, which allows an attacker to inject and execute malicious commands when the file name or directory name contains shell metacharacters.