emacsclient-mail.desktop in Emacs 28.1 through 28.2 is...
Critical severity
Unreviewed
Published
Mar 9, 2023
to the GitHub Advisory Database
•
Updated Mar 5, 2025
Description
Published by the National Vulnerability Database
Mar 9, 2023
Published to the GitHub Advisory Database
Mar 9, 2023
Last updated
Mar 5, 2025
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification.
References