CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.
CVE
CVE-2024-39331
Severity
CRITICAL
CVSS
9.8
EPSS
1.31%
Original NVD Description
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Related CVEs
Other vulnerabilities affecting the same vendor(s)