Command Injection Flaw in Emacs Enables Remote Shell Command Execution
·
CVE-2025-1244 is a command injection vulnerability in the Emacs text editor that could allow a remote, unauthenticated attacker to execute arbitrary shell commands by tricking a user into visiting a specially crafted website or an HTTP URL with a redirect. Separately published advisories include authenticated root-level OS command injection issues in Lantronix EDS5000 2.1.0.0R3 and EDS3000PS 3.1.0.0R2 (CVE-2025-67034 through CVE-2025-67038 and CVE-2025-67041), an authentication bypass in EDS3000PS (CVE-2025-67039), and prototype pollution in Lodash 4.0.0 through 4.17.22, patched in 4.17.23 (CVE-2025-13465).