CVE-2022-48339 | GNU Emacs up to 28.2 htmlfontify.el hfy-istext-command file/srcdir os command injection (Nessus ID 242832)
A vulnerability classified as critical has been found in GNU Emacs up to 28.2. This affects the function hfy-istext-command of the file htmlfontify.el. The manipulation of the argument file/srcdir leads to os command injection.
This vulnerability is uniquely identified as CVE-2022-48339. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.