VYPR

Tramp

by Emacs

CVEs (2)

  • CVE-2026-79992HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation…

  • CVE-2007-5377Oct 12, 2007
    risk 0.00cvss —epss 0.00

    The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.