CVE-2026-79992: local shell command injection through the user field in emacs tramp
Peter Oliver <[email protected]>
| Newsgroups | gmane.emacs.devel |
|---|---|
| Message-ID | <[email protected]> |
I see that CVE-2026-79992 has been reported against TRAMP, but is quite vague (https://www.cve.org/CVERecord?id=CVE-2026-79992). Does anyone know more about it, and whether it is already fixed on some branch(es)? I donΒ’t see anything obviously related in the Emacs bugtracker. -- Peter Oliver