A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-65616
https://bugzilla.redhat.com/show_bug.cgi?id=2523665
https://access.redhat.com/security/cve/CVE-2026-79992