GNU Emacs Git Forever-Day

Description

Zero-day dating back to 2018 in how GNU Emacs interacts with Git; exploitable simply by opening a file. Discovered by Claude Code on a follow-up prompt after the Vim finding. GNU Emacs maintainers declined to patch, classifying it as a Git issue rather than an Emacs issue — making it a 'forever-day' with only manual mitigations available. 8 years of unpatched exposure at disclosure.

Key claims

Relations

Sources

src-20260409-f5e09e325670