---
cve: "CVE-2024-53920"
severity: "HIGH"
cvss: 7.8
epss: "53%"
vendor: "n/a"
kev: false
exploited: false
published: "2024-11-27 15:15:26"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T21:30:52+02:00"
---

# CVE-2024-53920

> 7.8 HIGH

## Beschreibung

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4>
- <https://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92>
- <https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.html>
- <https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg@mail.gmail.com/>
- <https://news.ycombinator.com/item?id=42256409>
- <https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1>
- <http://www.openwall.com/lists/oss-security/2026/08/20/3>
- <http://www.openwall.com/lists/oss-security/2026/08/20/7>
- <http://www.openwall.com/lists/oss-security/2026/09/14/1>
- <https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-53920) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
